Tomorrow, a live webinar will delve into the intricacies of real-world Google Workspace breaches, shedding light on the tactics used by attackers to gain access to sensitive data. According to recent reports, these breaches often don’t rely on sophisticated exploits or stolen passwords, but rather on convincing users to grant unauthorized access through social engineering and malicious OAuth applications.
The webinar, “Breach autopsy: How fast-growing companies are breached through Google Workspace,” will feature Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC. Together, they will examine two publicly documented breaches that demonstrate how attackers exploit trust and application authorization to gain access.
These attacks are particularly concerning because they often go undetected until it’s too late. Once inside, the attackers can move freely within the Google Workspace environment, accessing sensitive data and connected applications. The speakers will dissect what happened during the critical first hours of these incidents, exploring which decisions made by security teams either limited or worsened their impact.
The webinar won’t focus on lengthy security checklists or theoretical best practices. Instead, it will provide a practical look at how real Google Workspace breaches unfold and the security measures that matter most for lean security teams. The speakers will discuss which Google Workspace security controls offer the greatest value and which may be overrated, as well as commonly overlooked weaknesses that can leave users and data exposed.
One of the key takeaways from this webinar is the importance of understanding what happens after initial access is discovered. Security teams need to quickly determine which users and data may have been compromised and make decisions that directly affect the scope and impact of the incident. By examining real-world breaches, the speakers will provide actionable insights on how to respond effectively in a crisis.
The discussion will also touch on the often-overlooked aspect of security: what happens when an attacker is already inside. The speakers will explore which response decisions can limit or worsen the impact of an incident and share practical security improvements that organizations can implement quickly, ranked by effort and potential impact.
For those interested in learning from actual incidents rather than theoretical best practices, this webinar promises to be a valuable resource. By attending, attendees will gain a deeper understanding of how attackers operate within Google Workspace environments and what steps they can take to improve their own security posture.
In conclusion, the upcoming webinar offers a unique opportunity for security teams to learn from real-world breaches and implement practical improvements that can have a significant impact on their organization’s security. Whether you’re a seasoned security professional or just starting out, this event is sure to provide valuable insights and actionable advice for protecting your organization’s sensitive data and connected applications.
Source: Bleeping Computer — 2026-09-22