← Back
Category 14: Channel Security, Account Safety, Phishing & Hack Prevention

Mailbox delegates can access recovery or security emails but are not included in the incident-response plan.

Problem

Mailbox delegates can access recovery or security emails but are not included in the incident-response plan.

Solution

Root Cause / Diagnostic:
Gmail delegation permits authorized secondary users to read, send, and delete emails without logging in with primary credentials. When incident response protocols overlook delegates, an attacker operating through a compromised delegate account can manipulate recovery flows undetected.

Actionable Fix:
1. Audit all configured mailbox delegates via Gmail (Settings > Accounts and Import > Grant access to your account) and revoke unverified delegates immediately.
2. Formally document all approved delegate relationships within the channel's Incident Response Playbook, mandating immediate delegate session revocation during any suspected breach.
3. Restrict mailbox delegation capability in Google Admin Console (Apps > Google Workspace > Gmail > User settings > Mail delegation) to authorized senior leadership only.

Pro Tip:
Configure Google Cloud Pub/Sub audit logs to stream mailbox delegation change events directly to your security monitoring dashboard for instant detection.