Problem
An attacker compromises a business domain and uses it to send highly convincing phishing messages.
Solution
Root Cause / Diagnostic:
When an attacker gains control of a legitimate corporate email account or misconfigured subdomains, they send phishing lures internally and to partners from a trusted address. Because the messages originate from the authentic domain, spam filters and staff treat the malicious attachments as legitimate.
Actionable Fix:
1. Isolate the compromised account immediately by resetting credentials, invalidating OAuth tokens, and revoking active sessions via Google Admin Console.
2. Inspect mail logs to identify all recipients of the internal phishing campaign and issue an urgent out-of-band broadcast warning the team not to click links.
3. Implement outbound content filtering rules that quarantine outgoing messages containing macro-enabled files, archive files (.zip/.rar/.7z), or suspicious external URLs.
Pro Tip:
Deploy automated email banner warnings in Google Workspace for internal emails originating from newly created or recently modified internal user profiles.
When an attacker gains control of a legitimate corporate email account or misconfigured subdomains, they send phishing lures internally and to partners from a trusted address. Because the messages originate from the authentic domain, spam filters and staff treat the malicious attachments as legitimate.
Actionable Fix:
1. Isolate the compromised account immediately by resetting credentials, invalidating OAuth tokens, and revoking active sessions via Google Admin Console.
2. Inspect mail logs to identify all recipients of the internal phishing campaign and issue an urgent out-of-band broadcast warning the team not to click links.
3. Implement outbound content filtering rules that quarantine outgoing messages containing macro-enabled files, archive files (.zip/.rar/.7z), or suspicious external URLs.
Pro Tip:
Deploy automated email banner warnings in Google Workspace for internal emails originating from newly created or recently modified internal user profiles.