Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails. The messages can look ordinary because they come from real organizational domains, not newly created addresses often flagged by filters. That makes a familiar inbox channel harder to trust and easier to misuse. The activity is especially concerning for schools, colleges, […] The post Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails appeared first on Cyber Security News .
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails
By Tushar Subhra Dutta
August 13, 2026
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails.
The messages can look ordinary because they come from real organizational domains, not newly created addresses often flagged by filters. That makes a familiar inbox channel harder to trust and easier to misuse.
The activity is especially concerning for schools, colleges, and education organizations. A stolen account gives criminals a credible sender identity, mailing habits, and a domain reputation. Recipients may open a message that appears to come from a known institution.
Spamhaus said in a report shared with Cyber Security News (CSN) that it had observed the same target domain across multiple spam campaigns.
The researchers identified more than 450 compromised education domains using Google Workspace, while stressing that the activity is not limited to education.
The campaign shows how account compromise can amplify email fraud. Instead of relying only on spoofed addresses, attackers can send from a legitimate environment and blend into routine conversations.
The immediate risk is credential theft or payment fraud, while the compromised mailbox damages trust in the organization being impersonated.
Hackers Leveraging GoogleWorkspace Accounts
The reported operation does not describe a single malware family or a fixed phishing template. Its common thread is the abuse of genuine Google Workspace accounts after takeover.
That distinction matters: the account becomes the delivery mechanism, allowing criminals to distribute deceptive content from domains that recipients and security systems recognize.
Spamhaus did not publish the initial access method, message contents, or the full list of affected domains in the supplied material.
Organizations should not assume that one subject line, attachment type, or lure defines the threat. Any unexpected request for a sign-in, payment, document review, or account action warrants independent verification.
Trusted services have repeatedly been used to lend weight to malicious messages. In one recent Google-themed credential phishing campaign, attackers used familiar sign-in branding and redirect chains to lead recipients to a credential-stealing page.
It reinforces a lesson: a recognizable sender or platform is evidence to examine, not proof that a message is safe.
Education organizations face particular pressure because their domains serve changing groups of staff, students, parents, alumni, and partners.
Busy academic periods create a steady flow of notices and shared files. A message imitating a routine administrative request can be convincing when it reaches someone from an authentic institutional account.
Protecting Accounts and Recipients
Administrators should focus on stopping account takeover and limiting its reach.
Require multi-factor authentication for every Workspace account, remove legacy access paths where possible, and review recovery methods, forwarding rules, connected applications, and administrator privileges.
Suspicious sign-ins or new mail rules should trigger a prompt investigation, particularly on accounts that send mail to large groups.
Mail teams should watch for unusual sending volumes, unfamiliar recipients, repeated links, abrupt changes in message language, and logins from unexpected locations or devices.
❗️ A LARGE NUMBER OF @GOOGLEWORKSPACE ACCOUNTS ARE BEING COMPROMISED AND USED TO SEND #PHISHING AND #SCAM EMAILS – SEE SCREENSHOT ATTACHED.
WE’VE OBSERVED THE SAME TARGET DOMAIN ACROSS MULTIPLE #SPAM CAMPAIGNS.
EDUCATION APPEARS TO BE PARTICULARLY AFFECTED. SO FAR, WE’VE… PIC.TWITTER.COM/N4K4ZCRNCV
— Spamhaus (@spamhaus) August 12, 2026
They should make it simple for users to report suspicious mail. Guidance from the education sector threat trends emphasizes training faculty and staff to recognize targeted phishing, a useful safeguard when identities are abused.
Recipients should slow down before responding to requests involving passwords, money, files, or account changes.
Rather than replying or using the message’s links, they can confirm the request through a known phone number, saved contact, or portal. The email fraud safety guide also recommends checking the sender address and verifying links before clicking.
If an account is suspected of sending scams, organizations should reset credentials, revoke active sessions, inspect mailbox rules and authorized apps, preserve relevant logs, and alert likely recipients quickly.
Reviewing prior mail activity can identify recipients and reveal whether other accounts show the same signs. The response should include a calm warning that legitimate-looking email can still be malicious.
The key point is not to treat this as a problem confined to one provider or sector. The Google Classroom phishing incident showed how abuse of a legitimate education-related service can reach thousands of organizations.
Defenders need layered checks around identity, email behavior, and user verification so one compromised account does not become a broad scam platform.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks
Cyber Security
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Cyber Security News
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
Cyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
Cyber Security News
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?