Google Workspace breaches don’t always begin with sophisticated exploits or stolen passwords. Sometimes attackers simply convince users to grant them the access they need.
Tomorrow, September 23, BleepingComputer will host a live webinar titled “Breach autopsy: How fast-growing companies are breached through Google Workspace” with Material Security.
The webinar will feature Rajan Kapoor, Vice President of Security at Material Security, and Rick Fitzgerald, President of Fireside Consulting LLC, examining real, publicly documented Google Workspace breaches and the decisions organizations made during the critical first hours of an incident.
The discussion will include two attacks that combined social engineering with malicious OAuth applications to gain access to Google Workspace environments.
These attacks demonstrate how threat actors can exploit trust and application authorization rather than relying solely on stolen credentials or software vulnerabilities.
But gaining access is only the beginning of the story.
The speakers will examine what happened after the breaches were discovered, which decisions during the critical first hours helped limit or worsen their impact, and which overlooked weaknesses left users, data, and connected applications exposed.
The webinar will also look beyond lengthy security checklists to discuss which Google Workspace security controls provide the greatest value, which may be overrated, and what the speakers would prioritize if they were building a security program for a fast-growing company from scratch.
Attendees will receive a practical look at how real Google Workspace breaches unfold and the security and response measures that matter most for lean security teams.
From initial access to incident response
Understanding how attackers gain access is only one part of learning from a breach.
Once suspicious access is discovered, security teams need to understand what happened, determine what users and data may have been exposed, and make decisions that can directly affect the scope and impact of the incident.
By examining real Google Workspace breaches from initial access through the first hours of response, this webinar will provide a practical look at both sides of the problem: how attackers get in and what defenders can do next.
Rather than presenting another long list of best practices, the discussion will focus on lessons from actual incidents and the security improvements that can have the greatest impact for organizations with limited resources.
The upcoming webinar will cover:
- How attackers used social engineering and malicious OAuth applications to gain access to Google Workspace environments
- What happened during the first hours of real Google Workspace breaches
- Which response decisions can limit or worsen the impact of an incident
- Which security controls provide the greatest value and which may be overrated
- Commonly overlooked weaknesses that can leave users, data, and connected applications exposed
- Practical security improvements organizations can implement quickly, ranked by effort and potential impact
Join us tomorrow to see how real Google Workspace breaches unfolded and what security teams can learn from the attacks and the response that followed.



