This information is intended to assist with investigation and mitigation for a compromised organization Google account. Note: More investigation beyond the steps in this document may be necessary to determine the full extent of the event, including whether or not any other accounts were compromised or data was breached. In addition, following the organization’s incident response plan, if appropriate, is recommended.
Questions to consider:
- How did this incident start?
- When did this start?
- What happened?
- Which accounts were compromised (all accounts)?
- What other files/data were accessed?
- What other SSO systems were accessed?
- What other email messages were viewed/deleted/etc.?
- What passwords could be compromised via Google password manager?
- What can be changed to prevent this from happening in the future?
User Account Compromise Suspected/Known (Containment)
In the Google Admin Console, within the Users section
- Reset Password for the user
Within Security tab:
- Click on Sign-in Cookies and click Reset
- Connected applications and devices; click on the edit pencil and then delete (trash can) next to each application
- Suspend the user account as needed, during investigation
Widespread Accounts Compromised (Containment)
For a larger number of likely compromised accounts, consider bulk suspending the accounts, if needed. NOTE: testing this process before an event occurs or with a test OU is recommended. One option: use GAM for bulk account suspension. Another option: export users, modify their status to Suspended, and re-import user list:
- Download a CSV file for the users in the applicable group
- Open the CSV and locate the “New Status [Upload Only]” column. Enter “Suspended” next to the users you wish to suspend.
- Save the modified CSV file and upload it to the Admin console.
Google File Share as Phishing Source (Containment)
These steps create a blocklist for any external account that shared a Google Drive file as part of a phishing attempt. This process allows retroactive removal of shared malicious drive files from all users’ accounts, as well as preventing future malicious sharing. Keep in mind that any account added to this will not be allowed to share files, so if an external valid account was compromised, after confirming with the external organization that they have fully secured the account, the contact may later need to be removed from the blocklist.
- Create a blocklist security group and allow external members.
- Turn on Trust Rules in the Google admin console.
- Create a Trust rule:
Scope: top OU
Trigger: Drive > Receiving files
Condition: your blocklist group
Action: Block - Make sure the rule is active.
- Test it with a personal Gmail account. (Add personal account to blocklist group, then try to share a Drive file with your user account.)
Message Deletion (Containment)
The Plus version of Google Workspace allows for deletion of email messages from the inbox of recipients. To delete messages, in Investigation tool:
- Go to the investigation search (see “Accessing Google Investigation Search” below)
- Gmail message filter
- Add filter: Subject => Is => Full email subject
- Select all messages
- On top right, click on “…” and select Delete. This process requires retyping a phrase to verify deletion.
Messages will continue to show in the filter, but will now be deleted from inboxes.
Phishing Link (Containment)
To block any additional email messages from being received which include a link to a malicious domain, complete the following to set up a block rule. (NOTE: This will block any message containing a link to any URL within the domain.)
- Apps > Google Workspace > Gmail > Compliance.
- Select the appropriate OU on the left.
- Scroll to Content compliance and click Configure (or Add another rule).
- Set up the fields in the compliance box as follows:
Short description: Block [domain or link description]
Email messages to affect: Check Inbound (and Internal – receiving if desired).
Add expressions: Leave the dropdown as If ANY of the following match the message. Click Add.
Change the dropdown to Simple content match.
In the Content box, type or paste the malcious domain example: dodgysite.com
Click Save. - Define Expressions action:
Change the dropdown from Modify message to Quarantine message.
(Optional) If you chose Reject, enter a rejection notice like: Emails containing links to [domain] are not allowed. - Save the Rule:
Click Save or Add setting on the dialog box, and then click the blue Save button at the very bottom of the main Gmail compliance screen to apply the changes.
Turn off Offline Access (Containment)
Search for “Offline” and turn off offline access for: Gmail, Docs, Calendar
Additional Investigation
Accessing Google Investigation Search:
Education Plus Version: Log into Google Admin console, Security, Investigation Tool
Google Workspace Free Version: Go to Audit and Investigation page in the Admin console or search for “investigation”. May be under Reporting; may also be linked from the Google Vault.
Who received a known phishing email:
- Gmail message filter
- Add filter of Subject (Contains or Is) and part or all of the malicious message’s subject
Tip: Export this list to a spreadsheet for future refrence.
Who clicked the link:
- Gmail message filter
- For user sender is choose the phish sender’s account
- Recipient is and choose an account who received the message
- Find a copy of the email that was sent, then copy that email subject
- New search: Attribute subject is and paste the subject of the email sent
- Then deleted all the emails that were sent internally (Education Plus, only)
- Then check gmail log events
- Event is choose: link click
- Subject contains [subject of the email sent]
- For any user who appears in this search, force password change.
- Checked the login events for each of the users that had clicked the link; if any susupicious logins are detected, revoke all users’ session tokens and continue investigation for any users with compromised accounts.
When/Where/IP that logged into compromised account(s):
- Go back to the original user account that is now disabled
- Choose user log events
- Event is choose: successful login
- User contains: enter compromised user’s account
- Check the IP addresses of the log in events, ruled out the building IP and user’s home network IP. Compromised IP address may say “is suspicious” is true and country of origin may be different than the US.
- Find date and time of the compromise then check the user’s emails from then and prior to find any prior suspicious messages.
- Once find root cause email, check for other users who clicked the link in the root cause message
Note: original email compromise may have been occurred days/weeks prior to the latest email messages going out from the organization.
Did malicious IP use Google Takeout to mass-export?
- Look at Takeout log events
- Choose IP address contains [malicious IP]
Look at Single Sign On events (Were other systems accessed via SSO?)
- Look at SAML log events
- Choose IP address contains [malicious IP]
- If needed to further filter, choose Actor contains; choose the compromised account
Were contacts exported?
- Look at Contacts log events
- For Actor contains choose the compromised account
- Verify that contacts were exported (consider what information was exported—example: home phone numbers, addresses, etc.)
Check for Google Drive log events
These are only available for so long; check as soon as you know an account was compromised.
- Choose Google Drive log events
- IP address contains; choose the compromised IP address This will show documents that were shared, deleted, viewed, edited
Gmail events (emails accessed, forwarded, deleted)
These are only available for so long; check as soon as you know an account was compromised.
- Gmail log events=> IP address contains choose the compromised IP Address
- Check what email was accessed, forwarded, deleted
Additional User log events
- Choose User log events
- User contains choose the compromised account
Malicious Devices with Downloaded Data
Check for unusal devices logged into the compromised account, such as virtual macines via Devices > Mobile & Endpoints >Devices > “…” on far right: View Audit Info to see what data has been downloaded to a device.
Keep in mind that there may be a need to document everything and complete a data breach investigation before using Delete Device option or remote wipe (Plus version)
- If an unusal device is found, copy the Device ID for it.
- Device Log Events => Device ID is [saved from step 1]
Internet Activity
Consider review of the compromised user’s browser history in the time after the account was compromised.
Google Sites
Were any sites created during the time when the account was compromised?
Gmail Rules
Were any rules set (auto-reply? message forwarding?)
Google Vault
Check for draft email messages, deleted emails, files, history, etc. for compromised user
Other (non-Google) Systems
If the user stores passwords in Google or uses single sign-on for other systems, also check logs for those systems to see when the user’s account accessed the system/data.
Notifying Other Organizations
If the phishing attempt originated from a compromised valid account, call or email the originating organization’s IT department or main phone number.
If your organization’s compromised user emailed external contacts, notify those contacts or their technical support. In the notification, include:
- Sender
- Email subject
- Other confirmed and relevant information about the email such as details of what happens if the user clicks the link/opens attachment
- For notifications to technical support, obfuscate (change) any reference to malicious links, so the links don’t resolve. (Example: replace “https” with “hxxp” and add brackets “[.]” around dots in the link.)
- Include the advice that any user who clicked link/interacted with the email message should notify their technical support.
- If applicable, advise recipients to:
- Revoke all sign-in cookies/sessions
- After revoking, change password
Notes:
- Avoid advising whether or not recipients should delete the email message.
- Avoid statements regarding data being compromised or not compromised unless advised by legal counsel.
- Consider using a different account than the compromised account to send the notifications.
Additional Mitigation and Protection
- In Google Admin console search for “spoofing” (Settings for Gmail > Safety) and turn on every option and choose Quarentine for the actions. (Turn on “Apply future recommended settings automatically”, also.)
- Update the following for all organization’s users and devices: operating system, browsers (including Chrome and Edge as well as any other browsers used), any PDF software, and any word processing software.
- Consider either a deep scan or re-imaging/wiping and re-installing the operating system for any device where the user opened a malicious attachment or potentially interacted with malware via a link click.
- Consider changing passwords for all cloud-based systems as well as the computer password for each compromised user.
- Ensure email spoofing is prevented, if you have not already set up DMARC/DKIM/SPF:
- Set limits on max recipients by OU.
- Change Google session control expiry to 12 hours or less.
- Establish data region where Google data is stored (example: US-based servers, only).
- Enable enhanced malware and phishing protections.
- Verify that Ransomware detection is turned on (Education Plus).
- Enable Google Vault (data retention and incident investigation).
- Tuned role-based access (in addition to User and Super Admin, see the other the various administrator access types).
- Implement Data Loss Prevention rules– to alert for accidental sharing of data such as banking information, credit card information, social security numbers, etc.
- Consider FIDO2 phishing resistant options (passkey/security fob). Passkey for Google Admin accounts is highly recommended.
- If not already complete, create a blocklist for any future malicious Google Drive file sharing events. (See Google File Share section, above.)
- Consider whether to prevent offline sync/offline access.
- Inventory critical/sensitive data stored in Google; move this data to another secure storage method or delete unnecessary data.
Additional settings to consider:
- Context-Aware Access
- Automatic AI classification of Google Drive files
- Google Device Bound Session Credentials
Intelligence Sharing
Contact MOREnet Security for information sharing options within the state.
Report any of the following to the FBI via the ic3.gov website reporting tool:
- Bitcoin wallets identified in phishing attempts
- Situations involving financial compromise
Additional Resources
MOREnet Blog articles:
