Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methodidentity-impersonation-fraudfinancial-sector-threat

Phishing and Financial Fraud Campaigns Targeting Online Accounts and Payment Data

Updated 3mo agoFirst seen Feb 18, 20263 sources

Threat researchers reported multiple financially motivated social-engineering operations designed to steal credentials and enable downstream fraud. Malwarebytes documented a job-themed phishing campaign impersonating Google Forms via the lookalike domain forms.google.ss-o[.]com, using a generation_form.php script to generate personalized lure URLs and redirecting victims through a fake form to a credential-harvesting login flow (e.g., id-v4[.]com). The infrastructure also used redirection to local Google search pages as an anti-analysis tactic to reduce link sharing and researcher visibility.

Separately, Bridewell-reported activity described a Booking.com-themed, multi-stage phishing and fraud scheme targeting both hotel partners and guests: initial “complaint”/reservation lures drive staff to attacker-controlled portals using lookalike domains (including IDN homograph tricks) to harvest partner credentials, followed by account takeover and guest-facing fraud (including WhatsApp outreach using real booking details). A third report described the broader rise of Carding-as-a-Service (CaaS) marketplaces (e.g., “fullz” bundling and platforms such as Findsome and UltimateShop) and the supply chain feeding them (PhaaS credential theft, skimming, and malware), but it did not describe the same specific phishing incidents and should be treated as related background rather than part of the same event.

Share:
Phishing and Financial Fraud Campaigns Targeting Online Accounts and Payment Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 19, 20264mo ago

Second report confirms fake Google Forms credential-harvesting activity

A follow-up report reiterated that the job scam used fake Google Forms pages, per-victim tracking links, and the long-used id-v4[.]com phishing endpoint, which had been taken down by the time of reporting. It also highlighted a sample lure for a 'Customer Support Executive' role and recommended MFA, domain verification, and anti-malware protections.

Feb 18, 20264mo ago

Researchers disclose technical details of Booking.com fraud chain

On publication, reporting detailed the Booking.com-themed campaign's infrastructure and tactics, including look-alike domains, IDN homograph abuse, visitor fingerprinting, decoy sites, and Cloudflare CAPTCHA-protected payment pages. The disclosure also included mitigations such as enforcing MFA, monitoring anomalous sign-ins, and warning customers not to pay through chat-app links.

Job-themed fake Google Forms phishing campaign observed

Analysts observed a phishing campaign targeting job seekers with fake Google Forms pages delivered through email or LinkedIn messages. The operation used the lookalike domain forms.google.ss-o[.]com, personalized links generated by generation_form.php, and redirected victims to id-v4[.]com/generation.php to harvest Google credentials.

Jan 1, 20266mo ago

Booking.com phishing campaign begins targeting partners and guests

Bridewell researchers reported a renewed financially motivated phishing operation active since early January 2026 that impersonates Booking.com. The campaign targets accommodation partners first to steal credentials and then abuses compromised accounts and booking details to defraud guests for payment card data and money.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
2 linked
LinkedinGoogle Search
Organizations
3 linked
MalwarebytesLinkedinGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing and Financial Fraud Campaigns Targeting Online Accounts and Payment Data | Mallory