Cybersecurity experts have been sounding the alarm about the growing threat of account takeover (ATO) attacks on Google Workspace platforms. However, a recent wave of breaches at Vercel and Composio suggests that these incidents are not isolated events, but rather the same attack pattern being executed against different targets. This revelation has significant implications for how we approach security in the age of artificial intelligence.
The traditional mental model of workspace security held that email was the primary entry point for attackers, with credentials stolen through phishing and then used to access sensitive data in Gmail and Drive. However, this model no longer holds true as attackers have adapted their tactics to chain together multiple exploits within the workspace, rather than relying solely on phishing.
A closer examination of these recent breaches reveals a new pattern: OAuth tokens are being used as the entry point into email accounts, rather than credentials stolen through email. This shift in tactics allows attackers to bypass traditional security measures and gain access to sensitive data stored in Gmail and Drive. Once inside, they can use this access to execute ATO attacks, taking over email accounts and using them to move laterally across connected systems.
This evolution of the workspace attack chain has significant implications for security teams. No longer can we rely on email-centric defenses; instead, we must focus on monitoring app behavior and detecting anomalies in OAuth token usage. This requires a fundamental shift in our approach to security, one that acknowledges the growing role of artificial intelligence in these attacks.
The use of AI in these attacks is particularly concerning, as it allows attackers to scale their efforts and sniff out vulnerabilities more effectively than ever before. As we move forward, it’s essential that we recognize the changing landscape of cybersecurity threats and adapt our defenses accordingly. This means investing in technologies that can detect and prevent OAuth token-based attacks, as well as developing new strategies for monitoring app behavior and detecting anomalies.
Ultimately, the recent breaches at Vercel and Composio serve as a stark reminder that cybersecurity is a constantly evolving field. To stay ahead of these threats, we must remain vigilant and adapt our defenses to meet the changing needs of an increasingly sophisticated threat landscape. By acknowledging the growing role of AI in these attacks, we can take proactive steps to protect our systems and prevent future breaches.
For individuals and organizations using Google Workspace platforms, this means taking a more holistic approach to security. This includes monitoring app behavior, detecting anomalies in OAuth token usage, and investing in technologies that can detect and prevent ATO attacks. By doing so, we can stay ahead of the evolving threat landscape and protect our sensitive data from falling into the wrong hands.
Source: Bleeping Computer — 2026-08-14