Phish of the Week: Adobe Summit 2027 Impersonation with Browser-in-the-Browser Credential Harvester
Adobe's flagship conference, Adobe Summit, is being impersonated with a personalized "complimentary pass" email that leads to a Google credential harvester. Because the campaign relies on curiosity and professional flattery rather than pressure, it can slip past recipients trained to watch for more obviously aggressive phishing tactics.
How the attack works:
The recipient receives an email formatted like a physical event ticket, complete with a boarding-pass style footer and barcode. It offers a complimentary pass to "Adobe Summit 2027," addressed to the recipient by name, and lists a full agenda of keynote sessions, product demos, and networking events. The email is sent from "Adobe Summit", using ON24, a legitimate webinar and virtual event platform. The stated event dates in the email do not correspond to the official Adobe Summit 2027 dates.
Clicking "Accept Invitation" leads to a landing page built to resemble a real event registration site, styled after the event platform Luma. The page repeats the personalization, again addressing the recipient by name, and displays a full event description for "Adobe Summit 2027" covering the same themes as the email. However, the event date shown on this page differs from the date stated in the original email.
Accepting the invitation moves to a confirmation screen with a visible countdown timer and a single option to proceed: "Continue with Google." The countdown discourages the recipient from pausing to verify the invitation and offers no alternative sign-in method.
Clicking the button opens what appears to be a separate browser window showing what looks like a legitimate Google address. In reality, this window is a Browser-in-the-Browser (BitB) pop-up: an image of a browser window rendered inside the page itself rather than a genuine, separate browser window. Any credentials entered here are sent to the attacker.
Why the attack works:
The attack layers several independent trust signals. The email carries real event branding and a creative, ticket-style design; the landing page repeats the personalization and event details; and the final sign-in screen references a well-known authentication method, "Continue with Google." Each step reinforces the one before it, so a recipient who has already accepted the premise of the first email has little reason to question the later steps.
The lure itself is built on curiosity and professional aspiration rather than fear. An unexpected invitation to a well-known industry event appeals to flattery and interest rather than threat, which makes it less likely to trigger the kind of caution that more aggressive phishing themes provoke.
Sending the email through a real third-party event platform is a deliberate evasion technique. Because the sending infrastructure is genuinely used for corporate webinars and events, it does not carry the reputation red flags of a freshly registered look-alike domain, and it can pass basic sender-reputation checks that would catch a more obvious spoof.
The final credential harvester is difficult to detect. A Browser-in-the-Browser pop-up is an image of a browser window, complete with a fake address bar, drawn inside the existing page rather than opened as a genuine new window. This means it can display any URL it wants, including one that looks like a legitimate Google sign-in address, and most recipients have no reason to suspect a pop-up window is not what it appears to be.
How to spot similar attacks:
- An unsolicited "VIP" or "complimentary" invitation to an event you never registered for
- A sender domain unrelated to the impersonated brand
- Information changes or don't match between the email and the linked landing page
- A countdown timer paired with only one option to continue, leaving no time to pause and consider alternatives
- A sign-in pop-up window that cannot be dragged, resized, or moved outside the browser's main content area
When in doubt about an event invitation, navigate to the organizer's official website independently rather than clicking through the email.
What is Phish of the Week?
Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.