Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Google Workspace Breaches Made Easy: Malicious OAuth Apps Exploit User Trust

A growing concern in cybersecurity is the ease with which attackers can breach sensitive data, even without exploiting software vulnerabilities or stealing passwords. Google Workspace, a suite of productivity and collaboration tools, has become a prime target for malicious actors who use social engineering tactics combined with malicious OAuth applications to gain unauthorized access.

On September 23rd, experts Rajan Kapoor and Rick Fitzgerald will share their insights on two real-world attacks that utilized this tactic in a live webinar hosted by Material Security. During the session, they will dissect how these breaches occurred, highlighting the weaknesses exploited and the critical decisions made during the initial hours of the incidents. Attendees will gain valuable knowledge on which security controls are most effective for fast-growing organizations with limited resources.

The malicious OAuth application attack vector is based on the authorization process that allows users to grant permissions to applications without sharing their passwords. While this feature streamlines connections between legitimate apps and Google Workspace, it also leaves room for abuse by attackers who use social engineering tactics to convince victims to authorize access to sensitive information. These manipulations can occur when a user believes they are connecting a trusted application or responding to a genuine request.

The resulting breach depends on the permissions granted during this process, making it essential for organizations to monitor third-party applications and ensure that users only authorize access to legitimate apps. By analyzing two attacks that combined malicious OAuth applications with social engineering tactics, the webinar will provide practical insights into how these breaches occur and what defenders can do to mitigate their exposure.

The experts will cover critical topics, including:

* How attackers combine social engineering and malicious OAuth applications to target Google Workspace environments

* The manipulation of users into authorizing application access

* The response decisions made during the initial hours of a breach and which ones matter most

* Which security controls provide the greatest value for fast-growing companies with limited security resources

Attendees will also learn practical security improvements that can be implemented quickly, ranked by effort and potential impact. By understanding how these breaches happen and what defenders can do to reduce their exposure, organizations can better protect themselves against this emerging threat.

To secure your spot at this informative webinar, register now and join the conversation on how malicious OAuth applications and social engineering can lead to Google Workspace breaches. With this knowledge, you’ll be equipped to prioritize security improvements that will help safeguard your organization’s sensitive data.


Source: Bleeping Computer — 2026-09-14