This information is intended to assist with investigation and mitigation for a compromised organization Google account. Note: More investigation beyond the steps in this document may be necessary to determine the full extent of the event, including whether or not any other accounts were compromised or data was breached. In addition, following the organization’s incident response plan, if appropriate, is recommended.
Questions to consider:
- How did this incident start?
- When did this start?
- What happened?
- Which accounts were compromised (all accounts)?
- What other files/data were accessed?
- What other SSO systems were accessed?
- What other email messages were viewed/deleted/etc.?
- What passwords could be compromised via Google password manager?
- What can be changed to prevent this from happening in the future?
Immediate First Steps (Containment)
In the Google Admin Console, within the Users section
- Reset Password for the user
Within Security tab:
- Click on Sign-in Cookies and click Reset
- Connected applications and devices; click on the edit pencil and then delete (trash can) next to each application
- Suspend the user account as needed, during investigation
Widespread Compromise (Containment)
For a larger number of likely compromised accounts, consider bulk suspending the accounts, if needed. NOTE: testing this process before an event occurs or with a test OU is recommended. One option: use GAM for bulk account suspension. Another option: export users, modify their status to Suspended, and re-import user list:
- Download a CSV file for the users in the applicable group
- Open the CSV and locate the “New Status [Upload Only]” column. Enter “Suspended” next to the users you wish to suspend.
- Save the modified CSV file and upload it to the Admin console.
Google File Share as Phishing Source (Containment)
These steps create a blocklist for any external account that shared a Google Drive file as part of a phishing attempt. This process allows retroactive removal of shared malicious drive files from all users’ accounts, as well as preventing future malicious sharing. Keep in mind that any account added to this will not be allowed to share files, so if an external valid account was compromised, after confirming with the external organization that they have fully secured the account, the contact may later need to be removed from the blocklist.
- Create a blocklist security group and allow external members.
- Turn on Trust Rules in the Google admin console.
- Create a Trust rule:
Scope: top OU
Trigger: Drive > Receiving files
Condition: your blocklist group
Action: Block - Make sure the rule is active.
- Test it with a personal Gmail account. (Add personal account to blocklist group, then try to share a Drive file with your user account.)
Additional Investigation
Accessing Google Investigation Search:
Education Plus Version: Log into Google Admin console, Security, Investigation Tool
Google Workspace Free Version: Go to Audit and Investigation page in the Admin console or search for “investigation”.
Who clicked the link:
- Gmail message filter
- For user sender is choose the phish sender’s account
- Recipient is and choose an account who received the message
- Find a copy of the email that was sent, then copy that email subject
- New search: Attribute subject is and paste the subject of the email sent
- Then deleted all the emails that were sent internally (Education Plus, only)
- Then check gmail log events
- Event is choose: link click
- Subject contains [subject of the email sent]
- For any user who appears in this search, force password change.
- Checked the login events for each of the users that had clicked the link; if any susupicious logins are detected, revoke all users’ session tokens and continue investigation for any users with compromised accounts.
When/Where/IP that logged into compromised account(s):
- Go back to the original user account that is now disabled
- Choose user log events
- Event is choose: successful login
- User contains: enter compromised user’s account
- Check the IP addresses of the log in events, ruled out the building IP and user’s home network IP. Compromised IP address may say “is suspicious” is true and country of origin may be different than the US.
- Find date and time of the compromise then check the user’s emails from then and prior to find any prior suspicious messages.
- Once find root cause email, check for other users who clicked the link in the root cause message
Note: original email compromise may have been occurred days/weeks prior to the latest email messages going out from the organization.
Did malicious IP use Google Takeout to mass-export?
- Look at Takeout log events
- Choose IP address contains [malicious IP]
Look at Single Sign On events (Were other systems accessed via SSO?)
- Look at SAML log events
- Choose IP address contains [malicious IP]
- If needed to further filter, choose Actor contains; choose the compromised account
Were contacts exported?
- Look at Contacts log events
- For Actor contains choose the compromised account
- Verify that contacts were exported (consider what information was exported—example: home phone numbers, addresses, etc.)
Check for Google Drive log events
These are only available for so long; check as soon as you know an account was compromised.
- Choose Google Drive log events
- IP address contains; choose the compromised IP address This will show documents that were shared, deleted, viewed, edited
Gmail events (emails accessed, forwarded, deleted)
These are only available for so long; check as soon as you know an account was compromised.
- Gmail log events=> IP address contains choose the compromised IP Address
- Check what email was accessed, forwarded, deleted
Additional User log events
- Choose User log events
- User contains choose the compromised account
Internet Activity
Consider review of the compromised user’s browser history in the time after the account was compromised.
Google Sites
Were any sites created during the time when the account was compromised?
Gmail Rules
Were any rules set (auto-reply? message forwarding?)
Google Vault
Check for deleted emails, files, history, etc. for compromised user
Other (non-Google) Systems
If the user stores passwords in Google or uses single sign-on for other systems, also check logs for those systems to see when the user’s account accessed the system/data.
Notifying Other Organizations
If the phishing attempt originated from a compromised valid account, call or email the originating organization’s IT department or main phone number.
If your organization’s compromised user emailed external contacts, notify those contacts or their technical support. In the notification, include:
- Sender
- Email subject
- Other confirmed and relevant information about the email such as details of what happens if the user clicks the link/opens attachment
- For notifications to technical support, obfuscate (change) any reference to malicious links, so the links don’t resolve. (Example: replace “https” with “hxxp” and add brackets “[.]” around dots in the link.)
- Include the advice that any user who clicked link/interacted with the email message should notify their technical support.
- If applicable, advise recipients to:
- Revoke all sign-in cookies/sessions
- After revoking, change password
Notes:
- Avoid advising whether or not recipients should delete the email message.
- Avoid statements regarding data being compromised or not compromised unless advised by legal counsel.
- Consider using a different account than the compromised account to send the notifications.
Additional Mitigation and Protection
- Update the following for all organization’s users and devices: operating system, browsers (including Chrome and Edge as well as any other browsers used), any PDF software, and any word processing software.
- Consider either a deep scan or re-imaging/wiping and re-installing the operating system for any device where the user opened a malicious attachment or potentially interacted with malware via a link click.
- Consider changing passwords for all cloud-based systems as well as the computer password for each compromised user.
- Ensure email spoofing is prevented, if you have not already set up DMARC/DKIM/SPF:
- Set limits on max recipients by OU.
- Establish data region where Google data is stored (example: US-based servers, only).
- Enable advanced phishing and malware protections.
- Enable Google Vault (data retention and incident investigation).
- Tuned role-based access (in addition to User and Super Admin, see the other the various administrator access types).
- Implement Data Loss Prevention rules– to alert for accidental sharing of data such as banking information, credit card information, social security numbers, etc.
- Consider FIDO2 phishing resistant options (passkey/security fob).
- If not already complete, create a blocklist for any future malicious Google Drive file sharing events (See Google File Share section, above.)
Additional settings to consider:
- Context-Aware Access (note: Context-Aware to date does not apply to logins to Google apps.)
- Automatic AI classification of Google Drive files
- Google Device Bound Session Credentials
Intelligence Sharing
Contact MOREnet Security for information sharing options within the state.
Report any of the following to the FBI via the ic3.gov website reporting tool:
- Bitcoin wallets identified in phishing attempts
- Situations involving financial compromise
Additional Resources
MOREnet Blog articles:
