ThreatBeaconXThreatBeaconXSubscribe
HighPhishing · 4 min read · 33 views

Hackers Leverage Compromised Google Workspace Accounts to Send Phishing and Scam Emails

Threat actors are abusing compromised Google Workspace accounts to send phishing and scam emails from legitimate organizational domains. Spamhaus identified more than 450 compromised education-sector domains, highlighting how stolen accounts can provide trusted sender identities and domain reputation to bypass traditional email defenses.

Written by ThreatBeaconX Research Team·Published Aug 13, 2026

Threat actors are increasingly abusing compromised Google Workspace accounts to distribute phishing and scam emails from legitimate organizational domains.

According to Spamhaus research reported by Cyber Security News, more than 450 compromised education-sector domains have been observed participating in phishing and spam campaigns.

The technique is particularly effective because attackers are not simply spoofing an organization's email address. Instead, they are using a legitimately compromised account to send messages from the organization's real Google Workspace environment.

Key Highlights

  • More than 450 compromised education domains observed.
  • Compromised Google Workspace accounts are used to distribute phishing and scam emails.
  • Attackers can abuse legitimate organizational domains and sender identities.
  • Messages can appear more trustworthy to recipients.
  • Education organizations are a major observed target.
  • The activity is not limited to the education sector.
  • Potential impacts include credential theft, payment fraud and further account compromise.

Abuse of Legitimate Accounts

Traditional phishing campaigns often rely on newly registered domains, spoofed addresses or suspicious sender infrastructure.

This campaign takes a different approach.

After compromising a Google Workspace account, attackers can use the legitimate account to send malicious emails.

This provides several advantages:

  • Legitimate organizational domain
  • Established sender reputation
  • Familiar sender identity
  • Normal-looking email infrastructure
  • Ability to communicate with external recipients
  • Greater chance of bypassing basic reputation-based filtering

The compromised mailbox effectively becomes part of the attack infrastructure.

Education Sector Targeting

Spamhaus identified more than 450 compromised education domains involved in the observed campaigns.

Schools, colleges and other educational organizations are attractive targets because their domains generally have established reputations and large numbers of external recipients.

A message sent from a legitimate educational domain may appear significantly more trustworthy than an email originating from an unrelated newly registered domain.

Phishing and Scam Delivery

The compromised accounts can be used to distribute different types of fraudulent messages.

Potential lures may include:

  • Credential verification
  • Account-related notifications
  • Document sharing
  • Payment requests
  • Invoice-related communications
  • Business correspondence
  • Urgent account actions

The campaign is not tied to one specific phishing template or malware family.

The common factor is the abuse of compromised Google Workspace identities to deliver malicious or fraudulent content.

Why the Technique Is Effective

Email recipients often rely on the sender's domain as an important trust signal.

When an email originates from a legitimate organizational domain, recipients may be less likely to question it.

The attacker therefore benefits from the organization's existing reputation.

This also creates a secondary impact: compromise of one mailbox can damage the reputation and trustworthiness of the entire organization.

Security Impact

The immediate risks include:

  • Credential theft
  • Business email compromise
  • Financial fraud
  • Malicious link delivery
  • Malware distribution
  • Further account compromise
  • Internal phishing
  • Reputation damage

If an attacker gains access to an account with extensive contacts or communication history, the compromised mailbox can become a highly effective platform for additional phishing campaigns.

Detection and Hunting Opportunities

Security teams should monitor for:

  • Unusual outbound email volume
  • Sudden increases in external recipients
  • Emails sent from accounts outside normal working patterns
  • Suspicious login locations
  • Impossible-travel authentication activity
  • New OAuth applications
  • Unexpected mailbox delegation
  • Suspicious forwarding rules
  • Unexpected changes to Gmail settings
  • Bulk outbound messages
  • Unusual email subjects or URLs
  • Account activity immediately following suspicious authentication events
  • Multiple compromised accounts sending similar messages

Google Workspace administrators can use the Investigation Tool and Gmail log events to identify affected users, message recipients, senders, subjects and message IDs, and can take remediation actions such as deleting malicious messages.

Recommended Mitigations

  1. Enable strong MFA for all Google Workspace accounts.
  2. Prefer phishing-resistant authentication where available.
  3. Monitor Google Workspace login activity.
  4. Review OAuth application permissions regularly.
  5. Monitor mailbox forwarding and delegation changes.
  6. Investigate unusual outbound email volumes.
  7. Restrict external forwarding where operationally possible.
  8. Review suspicious administrator and user activity.
  9. Use Google Workspace investigation capabilities to identify malicious campaigns.
  10. Immediately revoke active sessions after confirmed account compromise.
  11. Reset compromised credentials.
  12. Remove unauthorized OAuth applications.
  13. Notify recipients if a compromised account was used to distribute phishing emails.
  14. Monitor the organization's domain reputation following an account compromise.

Threat Assessment

Abusing legitimate Google Workspace accounts represents a significant phishing threat because attackers inherit the trust and reputation of the compromised organization.

The campaign demonstrates that email security cannot rely exclusively on sender-domain reputation. A legitimate domain and authenticated Google Workspace account can still be used to deliver malicious content when the underlying account has been compromised.

Conclusion

Organizations should treat unexpected outbound email activity from legitimate Google Workspace accounts as a potential security incident.

Security teams should combine identity monitoring, Gmail telemetry, OAuth auditing, mailbox-rule monitoring and email-content analysis to detect compromised accounts before attackers can use them for large-scale phishing and fraud.

MITRE ATT&CK Mapping

T1078 — Valid AccountsT1566.002 — Phishing: Spearphishing LinkT1586.002 — Compromise Accounts: Email AccountsT1098 — Account ManipulationT1114 — Email CollectionT1566 — Phishing