The Phishing Simulation Your Marketing Team Is Missing

Marketing professional at a laptop reviewing an email message

A phishing campaign that has been quietly running for at least five months just exposed a hard truth about employee training programs. When threat researchers at CTM360 published their RecruitTrap findings in August 2026, they mapped more than 3,000 phishing URLs impersonating recruiters from over 50 real organizations. The primary victims were marketing professionals, and the trap involved a fake browser window that most training modules have never shown employees.

For Canadian organizations investing in security awareness, the answer is not more generic e-learning. It is running phishing simulations that test real readiness against the campaigns your people will actually see this quarter. A modern phishing simulation program treats marketing and HR teams as first-class defenders, not as back-office generalists.

What CTM360 documented

CTM360’s RecruitTrap report identified more than 3,000 phishing URLs across roughly two months, impersonating recruitment processes tied to over 50 organizations across 14 industry sectors. The impersonated brands include Coca-Cola, Delta Air Lines, Adidas, Netflix, OpenAI, and FIFA, which gives the emails an air of legitimacy that generic phishing lures cannot match. Roughly 96 percent of the fraudulent pages used a Calendly-style scheduling theme, and many hid their real infrastructure behind Cloudflare.

The volume matters, but the pattern matters more. Attackers are no longer casting wide nets with typo-ridden invoice scams. They are running long-lived campaigns with real research on employee roles and career-relevant hooks. The Verizon 2026 Data Breach Investigations Report found that the human element remains involved in 62 percent of breaches, up from 60 percent the year prior. Recruitment lures land squarely inside that human element.

How the Browser-in-the-Browser trap works

The victim receives an email from what appears to be an internal recruiter and clicks a link to schedule an interview. That link leads to a counterfeit Calendly page or a brand-specific recruitment portal offering a “Continue with Google” or “Continue with Facebook” option. When the victim clicks, a fake pop-up window opens inside the current page. The pop-up mimics a real browser window, complete with a spoofed address bar and padlock icon, so the user believes they are on a genuine Google or Facebook login screen.

The credentials go straight to the attacker’s backend, which relays them to the real service in real time. If the account requires multi-factor authentication, the fake page also prompts for the code, sends it to the attacker, and lets the attacker complete the login. The victim is then redirected to a genuine Calendly page so nothing feels wrong. This is not a static credential form, it is a live relay that defeats push-based and one-time-code MFA.

Why marketing professionals are the target

CTM360 noted that marketing roles were deliberately over-represented among observed targets. A compromised marketing account can hand attackers access to advertising platforms, corporate social media, customer relationship management systems, email marketing lists, and analytics tools. That access enables everything from ad fraud and brand hijacking to secondary phishing campaigns launched from a trusted internal account.

The uncomfortable reality is that most Canadian awareness programs still centre on generic examples: the fake invoice, the CEO gift-card ask, the Microsoft 365 password reset. Marketing teams, HR teams, and other functions with unique attack profiles rarely see role-specific training, which is precisely the gap RecruitTrap exploits.

The Canadian angle every executive should notice

Canadian marketing professionals are on LinkedIn at the same rates as their US and European peers, and the RecruitTrap campaign is global in scope. The 2026 IBM Cost of a Data Breach Report puts the average Canadian breach at $7.11 million, and a marketing account takeover that leads to customer data exposure or brand-damaging content sits comfortably inside that cost band. For nonprofits and small enterprises, the reputational cost of hijacked social channels can eclipse the technical cost of remediation.

In our work running phishing simulations across Canadian organizations, we consistently see click rates that drop fast in the first quarter of a program and then plateau. The plateau is where most programs fail, because the easy gains are gone and the hard work of behaviour change begins. RecruitTrap sits on the far side of that plateau. Detecting a fake browser pop-up inside a real browser is not obvious, and it will not be learned from a video that plays once a year.

What to do this week

Start by adding a role-specific phishing scenario for marketing and HR teams that uses a recruiter or brand-partnership pretext. Brief employees that legitimate recruiters never funnel candidates through a Continue-with-Google pop-up, and that any interview link that requests a login should be closed and reported. For organizations that lack the internal capacity to build and rotate these scenarios, POPP3R’s managed security services can staff the program without pulling your IT team off other work.

On the technical side, require phishing-resistant MFA (passkeys or FIDO2 hardware keys) for marketing and social media accounts, since real-time credential relay defeats push and one-time-code methods. Review browser policies to block pop-ups by default on non-sanctioned sites, and confirm that your endpoint tooling logs the parent-child window relationships that reveal BitB behaviour. Finally, make reporting easy: a one-click phishing reporter and a public thank-you culture will surface these campaigns weeks before your first user loses credentials.

Sources