Skip to content
  • search.more.net
  • Missouri OER Hub
  • Support
  • MyMOREnet
MOREnet logo
  • Solutions
    • Connectivity
      • Internet Connection
        • Network Tools
          • Bandwidth Comparison Simulator
          • Bandwidth Download Simulator
          • Backbone Usage Map
          • Router Looking Glass
        • Service Notifications
        • Backup vs. Redundant Circuits
      • DNS Hosting
      • DNS Registration
      • E-Rate
        • E-Rate Support Material
          • E-Rate Training Schedule
          • E-Rate Training Videos
          • E-Rate Documents and Statistics
      • Internet2
      • WAN Connectivity
    • Security and Data Privacy
      • MSIP 6 Standards
      • Connection Security
        • Firewall
        • Akamai Secure Internet Access
          • A Missouri School District’s Experience With Akamai SIA
      • Employee and End-User Security and Education
        • Infosec IQ
        • Keeper
          • Keeper Security and Vault Transfer FAQs
      • Network Security
        • Virtual Servers
        • Content Filtering
          • Fortinet
          • Akamai Secure Internet Access
            • A Missouri School District’s Experience With Akamai SIA
        • Cybersecurity Assessment
        • Endpoint Detection and Response
          • Thirtyseven4
          • ThreatDown Powered by Malwarebytes
      • Data Privacy
        • Student Privacy
          • Missouri Student Privacy Alliance
          • The Education Cooperative (TEC) Data Privacy Agreement (DPA) Service
        • Privacy Best Practices
    • Network Solutions
      • Regional Support
      • LAN Services
        • Managed Networking
        • Threat Management Solution (powered by Fortinet)
        • Network Assessments
        • Network Consulting
      • Backup and Archiving
        • Network Backup
        • SecondWeb
      • Virtual Servers
      • Website Services
        • Web Hosting
        • Web Accessibility Guide
      • Wireless
        • Aruba
        • eduroam
        • Wireless Surveys
    • Classroom Tools and Resources
      • Online Resources
        • Included Online Resources with MSP
        • For Fee Online Resources
      • K-20 Interoperable Data Solution (KIDS)
        • MOREnet KIDS
        • KIDS Ed-Fi
      • Missouri OER Hub
    • Collaboration
      • Discussion Lists
      • Microsoft Licensing
    • Consortium Discounts
  • Community
    • Community
    • Professional Development
      • Training Schedule
        • On-Demand Training
      • Artificial Intelligence
      • The MILL
      • Computer Science Standards
        • Computer Science Training
      • Getting Started With Tech
      • Course Information
        • In-services
        • Trainer Profiles
        • Graduate Credit
        • Contracted Training
      • Subscribe to our Newsletter
    • Events
      • Annual Conference
      • Technical Training Summit
      • Summer Training
      • QCaMP
      • Student Data Privacy Regional Discussions
      • Columbia Sleeping Room Rates for In-person Training
    • Missouri Cybersecurity Challenge
      • Missouri Cybersecurity Challenge – FAQ
    • Collaborations
      • eduroam
      • Esports
      • K12TechPro
      • Public-Private Partnerships
        • Research and Education Networks
  • Membership
    • Membership
      • MyMOREnet
    • K-12 Public and Private
    • Public Library
      • REAL Program Goals
      • REAL Policies
        • REAL Membership
        • Connectivity
          • Connection Upgrade Process
          • Wireless Access at REAL Program Libraries
        • REAL E-Rate Requirements
    • Higher Education
      • Missouri Higher Education Information Technology (MoHEIT)
        • MoHEIT 2026 Meeting Presentations
    • Nonprofit and Agency
    • Affiliates
  • Blog
Home ▸ Blog ▸ Detailed Tips for Investigating a Google Account Compromise 

Detailed Tips for Investigating a Google Account Compromise 

This information is intended to assist with investigation and mitigation for a compromised organization Google account. Note: More investigation beyond the steps in this document may be necessary to determine the full extent of the event, including whether or not any other accounts were compromised or data was breached. In addition, following the organization’s incident response plan, if appropriate, is recommended. 

Questions to consider: 

  • How did this incident start? 
  • When did this start? 
  • What happened? 
  • Which accounts were compromised (all accounts)? 
  • What other files/data were accessed? 
  • What other SSO systems were accessed? 
  • What other email messages were viewed/deleted/etc.? 
  • What passwords could be compromised via Google password manager? 
  • What can be changed to prevent this from happening in the future? 

Immediate First Steps (Containment) 

In the Google Admin Console, within the Users section 

  1. Reset Password for the user 

Within Security tab:                                                                                                                                    

  1. Click on Sign-in Cookies and click Reset 
  2. Connected applications and devices; click on the edit pencil and then delete (trash can) next to each application 
  3. Suspend the user account as needed, during investigation  

Widespread Compromise (Containment)

For a larger number of likely compromised accounts, consider bulk suspending the accounts, if needed. NOTE: testing this process before an event occurs or with a test OU is recommended. One option: use GAM for bulk account suspension. Another option: export users, modify their status to Suspended, and re-import user list:

  1. Download a CSV file for the users in the applicable group
  2. Open the CSV and locate the “New Status [Upload Only]” column. Enter “Suspended” next to the users you wish to suspend.
  3. Save the modified CSV file and upload it to the Admin console.

Google File Share as Phishing Source (Containment)

These steps create a blocklist for any external account that shared a Google Drive file as part of a phishing attempt. This process allows retroactive removal of shared malicious drive files from all users’ accounts, as well as preventing future malicious sharing. Keep in mind that any account added to this will not be allowed to share files, so if an external valid account was compromised, after confirming with the external organization that they have fully secured the account, the contact may later need to be removed from the blocklist.

  1. Create a blocklist security group and allow external members.
  2. Turn on Trust Rules in the Google admin console.
  3. Create a Trust rule:
    Scope: top OU
    Trigger: Drive > Receiving files
    Condition: your blocklist group
    Action: Block
  4. Make sure the rule is active.
  5. Test it with a personal Gmail account. (Add personal account to blocklist group, then try to share a Drive file with your user account.)

Additional Investigation 

Accessing Google Investigation Search:

Education Plus Version: Log into Google Admin console, Security, Investigation Tool 

Google Workspace Free Version:  Go to Audit and Investigation page in the Admin console or search for “investigation”.   

Who clicked the link:

  1. Gmail message filter 
  2. For user sender is choose the phish sender’s account 
  3. Recipient is and choose an account who received the message 
  4. Find a copy of the email that was sent, then copy that email subject 
  5. New search: Attribute subject is and paste the subject of the email sent 
  6. Then deleted all the emails that were sent internally (Education Plus, only) 
  7. Then check gmail log events 
  8. Event is choose: link click  
  9. Subject contains [subject of the email sent] 
  10.  For any user who appears in this search, force password change. 
  11. Checked the login events for each of the users that had clicked the link; if any susupicious logins are detected, revoke all users’ session tokens and continue investigation for any users with compromised accounts. 

                    When/Where/IP that logged into compromised account(s):

                    1. Go back to the original user account that is now disabled 
                    2. Choose user log events 
                    3. Event is choose: successful login 
                    4. User contains: enter compromised user’s account 
                    5. Check the IP addresses of the log in events, ruled out the building IP and user’s home network IP. Compromised IP address may say “is suspicious” is true and country of origin may be different than the US. 
                    6. Find date and time of the compromise then check the user’s emails from then and prior to find any prior suspicious messages.  
                    7. Once find root cause email, check for other users who clicked the link in the root cause message 

                                Note: original email compromise may have been occurred days/weeks prior to the latest email messages going out from the organization. 

                                Did malicious IP use Google Takeout to mass-export? 

                                1. Look at Takeout log events 
                                2. Choose IP address contains [malicious IP] 

                                  Look at Single Sign On events (Were other systems accessed via SSO?)

                                  1. Look at SAML log events
                                  2. Choose IP address contains [malicious IP] 
                                  3. If needed to further filter, choose Actor contains; choose the compromised account 

                                  Were contacts exported?

                                  1. Look at Contacts log events 
                                  2. For Actor contains choose the compromised account 
                                  3. Verify that contacts were exported (consider what information was exported—example: home phone numbers, addresses, etc.) 

                                  Check for Google Drive log events 

                                  These are only available for so long; check as soon as you know an account was compromised. 

                                  1. Choose Google Drive log events
                                  2. IP address contains; choose the compromised IP address This will show documents that were shared, deleted, viewed, edited 

                                  Gmail events (emails accessed, forwarded, deleted)

                                  These are only available for so long; check as soon as you know an account was compromised. 

                                  1. Gmail log events=> IP address contains choose the compromised IP Address 
                                  2. Check what email was accessed, forwarded, deleted 

                                    Additional User log events

                                    1. Choose User log events
                                    2. User contains choose the compromised account 

                                    Internet Activity

                                    Consider review of the compromised user’s browser history in the time after the account was compromised.

                                    Google Sites

                                    Were any sites created during the time when the account was compromised?

                                    Gmail Rules

                                    Were any rules set (auto-reply? message forwarding?)

                                    Google Vault

                                    Check for deleted emails, files, history, etc. for compromised user

                                    Other (non-Google) Systems 

                                    If the user stores passwords in Google or uses single sign-on for other systems, also check logs for those systems to see when the user’s account accessed the system/data. 

                                    Notifying Other Organizations 

                                    If the phishing attempt originated from a compromised valid account, call or email the originating organization’s IT department or main phone number.  

                                    If your organization’s compromised user emailed external contacts, notify those contacts or their technical support.  In the notification, include: 

                                    • Sender 
                                    • Email subject 
                                    • Other confirmed and relevant information about the email such as details of what happens if the user clicks the link/opens attachment 
                                    • For notifications to technical support, obfuscate (change) any reference to malicious links, so the links don’t resolve. (Example: replace “https” with “hxxp” and add brackets “[.]” around dots in the link.)  
                                    • Include the advice that any user who clicked link/interacted with the email message should notify their technical support. 
                                    • If applicable, advise recipients to: 
                                    • Revoke all sign-in cookies/sessions 
                                    • After revoking, change password 

                                    Notes: 

                                    • Avoid advising whether or not recipients should delete the email message. 
                                    • Avoid statements regarding data being compromised or not compromised unless advised by legal counsel. 
                                    • Consider using a different account than the compromised account to send the notifications.

                                    Additional Mitigation and Protection

                                    • Update the following for all organization’s users and devices: operating system, browsers (including Chrome and Edge as well as any other browsers used), any PDF software, and any word processing software. 
                                    • Consider either a deep scan or re-imaging/wiping and re-installing the operating system for any device where the user opened a malicious attachment or potentially interacted with malware via a link click. 
                                    • Consider changing passwords for all cloud-based systems as well as the computer password for each compromised user.
                                    • Ensure email spoofing is prevented, if you have not already set up DMARC/DKIM/SPF: 
                                      • Email Spoofing 
                                      • Google Set up DMARC 
                                      • Google Set up DKIM 
                                      • Google Set up SPF 
                                    • Set limits on max recipients by OU. 
                                    • Establish data region where Google data is stored (example: US-based servers, only).
                                    • Enable advanced phishing and malware protections.
                                    • Enable Google Vault (data retention and incident investigation).
                                    • Tuned role-based access (in addition to User and Super Admin, see the other the various administrator access types).
                                    • Implement Data Loss Prevention rules– to alert for accidental sharing of data such as banking information, credit card information, social security numbers, etc.  
                                    • Consider FIDO2 phishing resistant options (passkey/security fob).
                                    • If not already complete, create a blocklist for any future malicious Google Drive file sharing events (See Google File Share section, above.)

                                    Additional settings to consider:

                                    • Context-Aware Access  (note: Context-Aware to date does not apply to logins to Google apps.)
                                    • Automatic AI classification of Google Drive files 
                                    • Google Device Bound Session Credentials

                                    Intelligence Sharing

                                    Contact MOREnet Security for information sharing options within the state.

                                    Report any of the following to the FBI via the ic3.gov website reporting tool:

                                    • Bitcoin wallets identified in phishing attempts
                                    • Situations involving financial compromise

                                    Additional Resources 

                                    MOREnet Blog articles:  

                                    • Mitigating a Successful Phish
                                    • Google: Identify and Secure a Compromised Accounts (for admin) 
                                    • Google: Secure a Hacked Account (for admin) 
                                    • Google tips to secure a hacked account (for user) 
                                    • Gmail Quarantine 
                                    Blog, Employee and End-User Security and Education, Network Security, Security and Data PrivacyGoogle account compromise, phishing

                                    Post navigation

                                    Updated Top 10 Priorities for a Cybersecurity and Data Privacy Program
                                    Missouri Military Academy Wins Annual Missouri High School Cybersecurity Challenge

                                    Author

                                    Sonia Kesselring

                                    Published

                                    February 19, 2026

                                    Subscribe to our Blog

                                    Want to receive notifications when we post new blog entries? Sign up here!

                                    Subscribe

                                    About us

                                    • About MOREnet
                                    • MOREnet History
                                    • MOREnet Leadership
                                    • The MOREnet Network
                                    • Research

                                    Resources

                                    • Employment Opportunities
                                    • Backbone Usage Map
                                    • Questions or Comments?
                                    • Publications

                                    Policies

                                    • Service Policies
                                    • Terms and Conditions
                                    • Payment Policy
                                    • Membership Pricing Information
                                    • Accessibility

                                    Connect with us

                                    • Contact Us
                                    • Locate Us
                                    • X (Twitter)
                                    • LinkedIn
                                    • Facebook

                                    Subscribe to Our Newsletter

                                    Sign up for our monthly newsletter about professional development opportunities and resources for educators.

                                    Subscribe

                                    Copyright © Curators of the University of Missouri. All rights reserved. Copyright, DMCA, privacy information
                                    Proudly powered by WordPress | Education Hub by WEN Themes