skillbitThe link looks safe.
That is the problem.
Modern phishing no longer fakes a website. It borrows the trust of a real one. Here are four live campaigns that abuse Meta, Apple, Microsoft, and Zoom against you, shown in real captures, and what it takes to stop them.
For years, phishing training gave people a simple rule: check the link. That advice still matters. But it is starting to feel incomplete.
Some of the most interesting phishing attacks today are not built around obviously fake domains, broken English, or strange attachments. They are built around trusted platforms that employees already use: Meta, Microsoft, Zoom, Apple, Google, Dropbox, DocuSign, and dozens of other SaaS tools.
The attacker's goal is not always to make a fake website look real. Increasingly, the goal is to use a real platform in a malicious way. A user might see a real Meta notification. A real Zoom sender. A Microsoft Customer Voice page. An Apple TestFlight install flow. Nothing about the first step feels obviously wrong, because in many cases the infrastructure really is legitimate.
The danger starts when the user assumes that a trusted platform makes every next click safe. The four campaigns below are all real, all documented by security researchers in 2025, and all built on exactly that assumption.
The Meta Business Manager partner request
One recent campaign abuses Meta Business Suite partner requests. The attacker does not need to spoof Meta from the outside. They create a real partner request through Meta's own workflow, so Meta sends the notification from its real infrastructure. The sender looks right. The template looks right. SPF, DKIM, and DMARC all pass.
The malicious piece is buried inside the request. Because the auto-generated invitation button cannot be edited, the attacker names the fake business after a "partner program" and drops an off-domain link at the top of the message. For a marketer or agency employee, partner requests are a normal part of the day. That is what makes it effective. The email is not fake. The business process has been weaponized.
The right question is not only, "Did this really come from Meta?" It is, "Does the destination and the request actually make sense for Meta?"
The fake Meta Ads Manager app through TestFlight
Another campaign targets advertisers with a fake Meta Ads Manager app. Victims are pushed to install it through Apple TestFlight, and some variants reportedly reached the App Store before removal. That is a powerful trust signal. Most people do not think of Apple's app distribution as part of a phishing chain.
By routing the victim through TestFlight, the scam stops feeling like "click this random link" and starts feeling like "install this business tool." Once installed, the counterfeit app harvests credentials, cookies, tokens, and ad-account access.
The lesson is not "Apple is unsafe" or "TestFlight is bad." It is that trusted distribution does not automatically mean trusted intent. The user still has to ask: Why am I being asked to install this? Was I expecting it? Would I find the same app by going directly through the official provider?
Microsoft Customer Voice phishing
Microsoft Dynamics 365 Customer Voice is a legitimate survey product, which is exactly why attackers reach for it. Campaigns themed around invoices, voicemails, and shared documents send links to real customervoice.microsoft.com pages. The first page belongs to Microsoft. Inside it sits one more link, sometimes behind a CAPTCHA, that leads to a fake Microsoft login.
This is why "check the domain" is no longer enough by itself. A Microsoft page can still contain attacker content. A trusted page can still point somewhere else. Users need to learn to pause after the first click, not just before it.
Zoom abuse and trusted notification flows
Zoom-themed attacks follow the same pattern. Some abuse Zoom Docs or Zoom Events notifications; others wrap themselves in document, invitation, or payment alerts. The dangerous part may not be a meeting link at all. It may be a document link, an external redirect, a fake support number, or a credential page reached after the first, innocent-looking interaction.
The user still has to evaluate the action being requested. Is this actually a meeting? Is it asking me to download software I did not request? Is it sending me away from Zoom, or asking me to sign in to Microsoft after I clicked a Zoom document? Those are context questions. They are harder to teach than "look for typos," but they are far more useful against modern phishing.
You cannot teach this with a once-a-year slide that says "hover over links."
These attacks require pattern recognition. People need practice walking the whole sequence: sender, platform, link, destination, request, second click, credential prompt, download, and business context. That is a perfect fit for hands-on, scenario-based training, and it is exactly what SkillBit builds.
Imagine a short lab where a learner gets a real-looking Meta partner request and has to find where the trust breaks. A Zoom document notification whose sender is clean but whose next page asks for something strange. A Customer Voice page where the suspicious part is not the Microsoft domain, but the link embedded inside the survey. That kind of practice builds judgment, not just awareness.

The old lesson was: be careful before you click. The new lesson is: be careful even after the first click looks safe. Modern phishing is more contextual, more platform-native, and more dependent on abusing legitimate workflows. So the training has to become more contextual too.
Investigate the link. Train the judgment.
Autonomous AI agents that investigate every message the way an analyst would, follow every link and attachment to its end, and act in milliseconds. We open the link before your users do.
Book a Cambrient demo →
SkillBitHands-on, scenario-based cyber training that builds the judgment these attacks are designed to beat. Give your team the reps to spot a weaponized workflow before they click.
Explore SkillBit Labs →
skillbitScreenshots are real captures reproduced from published threat research for educational purposes, credited to Sublime Security, Cofense, and Keep Aware. Campaign analysis also draws on Check Point Harmony research. Cambrient and SkillBit are not affiliated with Meta, Apple, Microsoft, or Zoom; brand names are used only to identify the platforms abused in these attacks.







