When Google Workspace gets breached, the door is usually already open
Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

Key points
- Most Google Workspace breaches start with social engineering, meaning tricks that fool a person, not with advanced hacking tools.
- Old third-party apps still connected to a company's Workspace are a common back door attackers walk through.
- The first few hours after a break-in decide whether one mailbox is lost or the whole company is.
- Multi-factor authentication, a second check beyond a password, would blunt most of these attacks but is not switched on everywhere.
- A free webinar from Material Security, first flagged by BleepingComputer, walks through real cases and the controls that helped.
Google Workspace is where a lot of small and mid-sized companies live. Email, shared drives, calendars, chat, the lot. So when someone breaks in, they are not just reading messages. They are sitting inside the company's memory.
And here is the awkward part. The break-in is rarely glamorous.
How do the hackers actually get in?
Usually by asking. Not with code, with a convincing email or a fake login page. This is social engineering, a polite term for tricking a human being into handing over a password or approving a login prompt.
The other common route is a forgotten app. Years ago, someone at the company clicked "Allow" on a third-party tool that wanted access to Gmail or Drive. That tool is still connected. Nobody remembers it. If the tool's maker gets breached, or the token it holds leaks, the attacker inherits that access without ever touching a password.
In identity terms, this is an authorisation problem, meaning the app was allowed to do too much for too long, rather than an authentication problem, meaning proving who you are at the door. Both matter. Companies tend to watch the door and forget the guests already inside.
What happens in the first few hours?
Speed decides everything. An attacker who lands in one mailbox will try to spread within minutes. They set up mail forwarding rules so they keep seeing replies. They search the inbox for the words "invoice", "wire", "payroll" and "password reset". They message the finance team from the real account.
If nobody notices, one compromised login becomes a company-wide problem by lunchtime.
The defenders' job in that window is simple to say and hard to do: kill the active sessions, meaning force the attacker to log in again; rotate the password; revoke the app tokens they may have stolen; and check for new forwarding rules and new admin accounts.
Would multi-factor authentication have helped?
Honestly, yes, most of the time. Multi-factor authentication, where you need a second proof such as a code or a hardware key on top of your password, stops the majority of stolen-password attacks cold.
It is not magic. Attackers have learned to bypass text-message codes with real-time phishing pages, and to spam push notifications until a tired employee taps "approve". Hardware keys and passkeys, which use cryptography tied to your device, hold up much better. But even basic MFA raises the cost of an attack enough that many crews move on to an easier target.
The webinar itself
Material Security is running a free session walking through real Google Workspace breaches, what the first hours looked like, and which controls made the biggest difference. It is aimed at IT and security staff, but the case studies are readable for anyone who runs a business on Workspace.
Expect specifics on OAuth app sprawl, which is the pile-up of third-party connections nobody audits, and on session hijacking, where attackers steal the cookie that keeps you logged in and skip the password step entirely.
If you administer a Workspace tenant, it is an hour well spent. If you are a business owner who just uses Gmail for work, ask whoever handles your IT whether they have watched it.



