Gaining unauthorized access to organizational data through Google Workspace does not always require exploiting software flaws or compromising user credentials. Attackers have found an alternative path: leveraging the OAuth authorization mechanism itself.

Kernelwire will present a live webinar on September 23, 2026, titled "Breach autopsy: How fast-growing companies are breached through Google Workspace," developed in partnership with Material Security. The session will bring together Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, to dissect two real-world incidents in which attackers deployed malicious OAuth applications combined with social engineering tactics to compromise Google Workspace deployments.

The OAuth protocol enables users to authorize third-party applications to access Google Workspace resources and functionality without disclosing their passwords. This streamlines integration of legitimate tools, but the same mechanism becomes a vulnerability when threat actors craft deceptive authorization requests. By using social engineering, attackers can trick users into granting permissions to malicious applications, potentially unlocking access to sensitive data based on whatever permissions the user approves.

This attack vector underscores a critical gap in many organizations' security posture: the need to move beyond password protection and conventional authentication safeguards. Defenders must develop visibility into which applications have been authorized within their Google Workspace environment and what access each one possesses.

What the webinar will address

During the session, speakers will walk through the timeline and mechanics of both attacks, identify the specific weaknesses that enabled them to succeed, and review the critical decisions made by defenders in the immediate aftermath of discovery.

Material Webinar

Participants will also discover which defensive measures deliver the most value for organizations with limited security teams and budgets, and learn what priorities the speakers would establish if designing a Google Workspace security program from the ground up.

How social engineering enables OAuth abuse

Social engineering attacks traditionally focus on extracting passwords or other sensitive credentials from users. Malicious OAuth applications open a different avenue: persuading a user to voluntarily grant access to an attacker-controlled app.

A target may believe they are authorizing a legitimate service or responding to a request from a trusted source, when in reality they are enabling a malicious application to operate within their Google Workspace account. The scope of the breach depends entirely on which permissions the user authorized, making visibility and control over third-party application access essential.

Webinar agenda

  • Tactics attackers use to combine social engineering with malicious OAuth applications against Google Workspace
  • Methods used to manipulate users into authorizing application access
  • Key events and response decisions in the first hours following a Google Workspace breach
  • Security controls that deliver the highest return on investment for resource-constrained organizations
  • Actionable security improvements ranked by implementation effort and potential impact