A Workspace identity is phished
The attacker lures a user to a look-alike sign-in flow and captures their credentials, and in adversary-in-the-middle style lures the active session, allowing them to act as the user.
Capture a valid Google Workspace login and, ideally, the resulting session.
- Phishing-resistant MFA (security keys / passkeys)
- Context-aware access policies for Workspace
- User reporting and rapid lure takedown
- Logins from new locations, devices or unusual ASNs
- Suspicious-login alerts from the admin console
- Session activity inconsistent with the user's norms
- Social-engineering assessment measuring click and report rates
- Test whether the MFA method can be relayed
- Review context-aware access coverage
The attacker can now act as a legitimate user within Workspace.