Breaches targeting Google Workspace frequently bypass technical defenses entirely. Rather than exploiting software flaws or obtaining credentials through theft, threat actors often manipulate users into voluntarily granting access to their accounts and data.
On September 23, BleepingComputer will conduct a live webinar in partnership with Material Security titled "Breach autopsy: How fast-growing companies are breached through Google Workspace." The session will bring together Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, to analyze documented incidents and the organizational decisions made during the critical opening phase of response.
The presentation will focus on two separate incidents where attackers combined social engineering tactics with malicious OAuth applications to infiltrate Google Workspace deployments. These cases illustrate how adversaries can weaponize trust and application permissions as an alternative to credential compromise or software exploitation.
From initial access to incident response
Understanding the entry point represents only a fraction of the breach picture. When suspicious activity surfaces, defenders must reconstruct what occurred, identify which users and information faced exposure, and make choices that directly shape the incident's scope and severity.

By analyzing actual Google Workspace breaches from the moment of compromise through the opening hours of containment, the webinar will address both dimensions of the problem: the methods attackers employ and the countermeasures available to security teams. Rather than reciting generic security checklists, the speakers will draw on lessons from real incidents and highlight the improvements that deliver maximum value for resource-constrained organizations.
Topics covered in the webinar
- How attackers used social engineering and malicious OAuth applications to gain access to Google Workspace environments
- What happened during the first hours of real Google Workspace breaches
- Which response decisions can limit or worsen the impact of an incident
- Which security controls provide the greatest value and which may be overrated
- Commonly overlooked weaknesses that can leave users, data, and connected applications exposed
- Practical security improvements organizations can implement quickly, ranked by effort and potential impact
The session will deliver actionable insights into how Google Workspace breaches develop in practice and which security and response strategies matter most for teams operating with constrained budgets and personnel.