Recruitment-Themed Phishing Campaign Targets Enterprise Users
KnowBe4, Wednesday, September 2nd, 2026
Attackers impersonate real HR staff and use Browser-in-the-Browser popups to steal enterprise credentials from job seekers.
KnowBe4 highlights research from Zimperium tracking widespread phishing campaigns that rely on Browser-in-the-Browser (BitB) attacks to harvest enterprise credentials.
The attackers impersonate real HR employees at major companies and target job seekers with highly realistic interview processes.
Because the fake browser window is rendered inside the page, victims see what looks like a legitimate corporate sign-in prompt. The campaign shows how recruitment lures combined with convincing UI spoofing can bypass the visual cues users are normally trained to check.