Check Point detects global phishing attack targeting 13,500+ Google Classroom users

By: 

Expression Africa

Check Point researchers have uncovered a large-scale active phishing campaign abusing Google Classroom, a platform trusted by millions of students and educators worldwide. 

Over the course of just one week, attackers launched five coordinated waves, distributing more than 115,000 phishing emails aimed at 13,500 organisations across multiple industries.

Thus far, organisations in Europe, North America, the Middle East, and Asia are being targeted.

According to Check Point’s July 2025 Top Malware Report, the education sector was the most targeted globally, averaging 4,210 weekly attacks per organisation (+24% YoY).  In comparison, a South African education organisation has been attacked on average 2225 times per week in the last six months.

Turning a trusted tool into a threat vector

Google Classroom is designed to connect teachers and students through invitations to join digital classrooms. Attackers exploited this trust by sending fake invitations that contained unrelated commercial offers, ranging from product reselling pitches to SEO services. 

Each email directed recipients to contact scammers via a WhatsApp phone number, a tactic often linked to fraud schemes.

Example of the phishing emai
Example of the phishing email

The deception works because security systems tend to trust messages originating from legitimate Google services.

By piggybacking on Google Classroom’s infrastructure, attackers were able to bypass certain traditional security layers, attempting to reach inboxes at more than 13,500 companies before defenses were triggered.

Anatomy of the campaign
  • Scale: 115,000 phishing emails sent between August 6–12, 2025
  • Targets: 13,500 organisations worldwide, spanning multiple sectors
  • Lure: Fake Google Classroom invitations with offers unrelated to education
  • Call to action: A WhatsApp phone number, designed to move the conversation off-email and outside enterprise monitoring
  • Delivery method: Five major waves, each leveraging Google Classroom’s legitimacy to slip past filters
How Check Point blocked the attack

Despite the attackers’ sophisticated use of trusted infrastructure, Check Point Harmony Email & Collaboration’s SmartPhish technology automatically detected and blocked the majority of these phishing attempts.

Additional layers of security prevented the remaining messages from reaching end users.

“This incident underscores the importance of multi-layered defenses. Attackers are increasingly weaponising legitimate cloud services — making traditional email gateways insufficient to stop evolving phishing tactics,” says security evangelist for Check Point Software Technologies, Shayimamba Conco.

What organisations should do
  1. Educate users: Train employees to treat unexpected invitations (even from familiar platforms) cautiously.
  2. Deploy advanced threat prevention: Use AI-powered detection that analyses context and intent, not just sender reputation.
  3. Monitor cloud applications: Extend phishing protection beyond email to collaboration apps, messaging platforms, and SaaS services.
  4. Harden against social engineering: Be aware that attackers increasingly push victims toward off-channel communications (like WhatsApp) to evade enterprise controls.
The bottom line

“Attackers continue to find creative ways to exploit legitimate services like Google Classroom to gain trust, bypass defenses, and reach targets at scale. With over 115,000 emails in just one week, this campaign highlights how easily cyber criminals can weaponise digital platforms for fraud,” concludes Conco.

Recognised as a leader and outperformer in the 2025 GigaOm Radar for Anti-Phishing, Check Point Harmony Email & Collaboration provides the advanced, layered defense needed to secure organisations against phishing attacks — even when they hide in plain sight.

Hot this week

Kenya tops DDoS threat list in East Africa – NETSCOUT Threat Intelligence Report

According to the results analysed from the release of...

Kenya: Meta partners with Safaricom to land new submarine cable

Meta has entered a deal with Safaricom to bring...

Stanbic Bank facilitates $45m cross-border financing to boost PepsiCo Bottlers’ growth in East Africa

Stanbic Bank Kenya and Stanbic Bank Uganda, both members...

Businesses flock to Ethiopia’s newly-opened banking market

Ethiopia’s banking market, once sealed off to foreign participation,...

Kigali facility revs up Africa’s vaccine self-reliance

A new European financial backing of BioNTech’s mRNA vaccine...
spot_imgspot_imgspot_img

Related Articles

Popular Categories

spot_imgspot_imgspot_imgspot_img