{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreidcqe3otrqpzkrjmo4haewbhxkeeq7rctsg5tzdgidp76syu4vjpa",
"uri": "at://did:plc:iir655mcoipvnewhnkv6fb3u/app.bsky.feed.post/3moyuazf3tuq2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreidz5het2m5q6houtow56shm7bgd72j5yvxgzrffn4362dyvudwosi"
},
"mimeType": "image/png",
"size": 232302
},
"path": "/blog/blog/ad-funded-phishing-heroku-azure-facebook-june-2026/",
"publishedAt": "2026-06-23T23:34:07.000Z",
"site": "https://pixmsecurity.com",
"textContent": "\nBetween June 16 and June 22, we detected phishing campaigns spanning tech support scams delivered via Facebook ads on Azure infrastructure, Microsoft credential harvesting hosted on Heroku and promoted through Google Ads, Paperless Post invitation lures targeting multiple email providers. What ties them together: these campaign abused trusted infrastructure both to host and deliver their attacks.",
"title": "Ad-Funded Phishing: How Facebook and Google Deliver Attacks to Enterprise Browsers"
}