← All posts

Google Workspace Account Compromised: Recovery Steps

September 16, 2026

A Workspace compromise hides in different places than Microsoft 365. Here is where to look and how to lock the domain back down.

Google Workspace compromises follow the same pattern as any email account compromise — quiet access, a hidden filter, a fraudulent invoice — but the controls and evidence live in different places.

Contain the account

From the Admin console, reset the password and sign the user out of all sessions. Then revoke application-specific passwords and the OAuth tokens under the user's Security tab. Tokens are the persistence mechanism that survives a password change, so treat that step as mandatory rather than optional.

Check the Workspace-specific hiding places

  • Filters and forwarding in Gmail settings, including "delete it" filters that suppress vendor replies
  • Delegated access, which lets another account read and send without a password
  • Send-as addresses added during the compromise
  • Connected apps and third-party OAuth grants with Gmail scopes
  • Vacation responders used to keep a fraud thread warm
  • 2SV enrollment, including backup codes and phone numbers the attacker added

Investigate with the audit logs

The login audit log shows successful and failed sign-ins with IP and app. The email log search shows message flow. Admin audit logs show configuration changes, which is how you tell whether the attacker touched the domain rather than just one mailbox. Export what you need — retention is finite, and a claim months later will require it.

Lock the domain down

Enforce 2SV for everyone, and require security keys or passkeys for finance, executives, and admins. Turn off less secure app access. Restrict who can create filters that forward externally, and enable alerts for suspicious login and for new forwarding. Review super-admin count and remove standing privilege that nobody uses.

Then look outward

If a vendor or customer received mail from that account, assume they were targeted too, and warn them directly by phone. Vendor email compromise spreads through exactly these trusted threads.

Our Google Workspace support team handles both the emergency and the hardening that keeps it from repeating.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

Google Workspaceaccount takeoverrecovery2SV

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.