Google Workspace Email Security: What Native Protection Misses in 2026

google-workspace-security

In June 2026, Google disclosed that a threat actor it tracks as UNC6508 had gained access to a Google Workspace administrator account using credentials taken during an earlier compromise. The attacker then created a domain-wide content compliance rule that silently BCC-forwarded matching sent and received emails to an attacker-controlled Gmail account.

Google described the manipulation of content compliance rules for data exfiltration as a novel technique and attributed the activity to UNC6508 with high confidence. Its recommendations included monitoring audit logs, reviewing compliance rules, using DLP, and ensuring Workspace logs are included in a SIEM.

The important point is that Google Workspace did not simply fail to detect malware. Its native security controls already cover a lot: phishing and malware protection, identity and login controls, DLP, audit logs, and security alerts.

The problem is what happens when an attacker gets legitimate access.

A compromised administrator can create mail rules, change settings, grant application access, and access data using the same tools an administrator would normally use. There may be nothing obviously malicious about the individual action.

This is where security needs to look beyond the message itself and into identity, configuration changes, third-party applications, and user behaviour.

The risk extends beyond the inbox

Two areas deserve particular attention: OAuth access and business email compromise.

When a user grants a third-party application access to Google Workspace, that authorisation can allow the app to access the data covered by the approved scopes. Google automatically revokes OAuth tokens for certain products and mail scopes when a user’s password is changed, including access used by third-party mail applications such as Apple Mail and Thunderbird. The policy does not apply universally across Workspace applications and scopes, so a password reset should not be treated as a complete response to a suspicious application authorisation.

Administrators should review third-party application access at the domain level and remove applications that are no longer required. Google provides controls in the Admin console to review applications, their requested services and OAuth access, and to restrict or block access where necessary.

Consent phishing makes this particularly relevant. An attacker can use Google’s legitimate OAuth flow to present a familiar authorisation screen and persuade a user to approve access.

The email itself can also pass normal authentication checks if it was sent from infrastructure controlled by the attacker.

Passing those checks confirms that the sending domain is authenticated. It says nothing about whether the message is trustworthy.

The other pattern is much closer to everyday BEC: a forwarding or filter rule created shortly after a login from an unusual location, quietly sending messages containing words such as “invoice” to an external address.

Regional threat researchers have seen similar behaviour. Help AG has documented a business email compromise campaign impersonating UAE government agencies and targeting vendor management teams involved in tender registration. The UAE Cyber Security Council has also reported that more than 75 percent of cyber breaches begin with phishing emails or fraudulent messages.

Three checks worth an hour this week

You do not need to buy another security product to start addressing these issues.

Start with the Google Workspace settings already available to your administrators.

  1. Review third-party applications

Go to Security > Access and data control > API controls > Manage Third-Party App Access and review applications with access to Gmail, Drive, and other Workspace services. Remove anything that is no longer required or cannot be accounted for. Google also allows administrators to control which third-party applications can access Workspace data.

  1. Review mail rules

Go to Apps > Google Workspace > Gmail > Compliance and review content compliance rules. Then review Gmail > Routing for routing rules, forwarding destinations, and other message-routing configurations. Look closely at rules that send copies of messages to external addresses. Every rule should have a clear business reason and an owner who can explain why it exists.

  1. Review Drive sharing

Review Drive sharing settings by organisational unit and restrict external or “Anyone with the link” access where it is not required.

These checks can uncover access and configuration problems before you start looking at another security product. From there, sending admin and mail audit logs to your SIEM and using phishing-resistant two-step verification for privileged accounts can provide another layer of protection. Google’s guidance following the UNC6508 campaign specifically recommends phishing-resistant 2SV for enterprise administrators, audit-log monitoring, DLP, and SIEM coverage for Workspace logs.

Where additional protection fits

Once the basic configuration is under control, organisations may still need additional protection against sophisticated phishing, BEC, post-delivery threats, and attacks that rely on a user making the wrong decision.

Several security vendors now offer protection specifically for Google Workspace.

Mimecast’s email security capabilities work with Google Workspace, and in July 2026 the company added Google Workspace signals to its Human Risk Command Center. These include Gmail phishing and post-delivery reclassification alerts and Google’s identity risk signals, such as suspicious logins and leaked credentials.

Proofpoint’s Core Email Protection supports Google Workspace through API-based protection and gateway deployment options. Proofpoint’s documentation describes protection for Google Workspace through Core Email Protection API, alongside its broader email security capabilities.

Fortinet’s FortiMail platform provides layered email security for Google Workspace, with support for cloud-based deployment and API-based integration. Fortinet’s documentation also describes scanning Google Workspace mailboxes through service APIs, with options for real-time scanning and remediation actions.

KnowBe4 added Google Workspace to its Defend email and collaboration security platform on 31 August 2026. The company says Defend uses a multi-engine behavioural AI model and combines threat detection with contextual coaching for users.

According to KnowBe4, its early-adopter programme processed 539,384 emails and identified 810 dangerous threats and another 5,491 suspicious messages that had passed Google’s native filtering. These figures are based on KnowBe4’s own early-adopter data and should be viewed as vendor-reported results.

The important difference between these approaches is how they work alongside Google Workspace. Some focus heavily on email inspection and remediation, while others extend into identity signals, user behaviour, or post-delivery response.

Which protection does your organisation need?

That depends on what is happening inside your Google Workspace environment.

If administrator accounts, OAuth applications, sharing settings, or mail rules are the concern, start there. If users are regularly dealing with sophisticated phishing and BEC, additional email protection may be the priority. If threats are getting through and being discovered only after delivery, post-delivery detection and remediation become more important. If users remain the final point of failure, behavioural protection can help intervene before a mistake becomes an incident.

This is where we help.

iConnect works with Mimecast, Proofpoint, FortiMail, and KnowBe4 to help organisations secure their Google Workspace environments. We can review your current configuration, identify where your existing controls leave gaps, recommend the right approach, and handle the implementation and integration with your existing security stack.

If you are using Google Workspace and want to understand how well your current email and collaboration security holds up against today’s threats, talk to our team about a Google Workspace security assessment.

Contact us

Talk to our team about your requirement

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Our Value Proposition
What happens next?
1

We’ll arrange a call at your convenience.

2

We do a discovery and consulting meeting 

3

We’ll prepare a detailed proposal tailored to your requirements.

Schedule a Free Consultation