Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Google Drive Mass Download Detection and Takeout Exports

Detect data theft in Google Workspace: Drive mass download bursts, external sharing, public links, owner transfers and Google Takeout exports in audit logs.

Published on 5 min read

TL;DR. Data theft in Workspace shows up in three logs. Drive has bursts of download events, files shared to external addresses or opened to "anyone with the link", and ownership transfers. Takeout records a full-account export being started, completed and downloaded. OAuth token records an app pulling Drive or Gmail data through the API. Look for volume in a short window, from an unusual IP, right after a suspicious sign-in. Then check whether your license tier logs Drive activity at all.

In a business email compromise the money is the goal, but data often leaves too: supplier lists, payroll, bank mandates, customer records. They are useful for the next fraud or for extortion. Drive and Takeout are where to look.

Drive events that matter

Google's Drive log events page documents the full list. For exfiltration:

Event (API name)Console title (English)Why it matters
downloadDownloadFile content left Google
change_user_accessChange user access / sharingFile shared with a person, possibly external
change_document_visibility, change_document_access_scopeChange visibility / link sharing"Anyone with the link" or public on the web
change_ownerChange ownerFile moved to another account's ownership
copy, view, editCopy, View, EditContext, and staging before download

Each record carries the actor, the document title, ID, type and owner, the visibility and the IP. The Reports API adds network information.

Pattern 1: mass download

One account downloading many files in minutes is rarely a person clicking. The analyzer flags 20 or more download events within 15 minutes by the same actor as Mass download of Drive files (high, T1530 Data from Cloud Storage). The finding lists the IPs and file titles. The evidence view shows every file.

Qualify it:

  • IP. The office network or a hosting ASN already seen in a risky sign-in?
  • Time. 02:00 local time on a weekday, when the user was asleep?
  • Files. A migration folder, or finance, HR and customer data picked across folders?
  • Client. Does the user run a sync client? Syncing or migrating a folder can produce legitimate bursts. Ask before you escalate.

A patient attacker downloading below the threshold won't trip the rule. Sort the All events view by actor and IP for the incident window anyway.

Pattern 2: sharing outward

Instead of downloading, an attacker can share files to an outside account and read them at leisure. That leaves nothing on your network.

  • External share burst: 10 or more files shared with external addresses, or switched to "anyone with the link" / public / shared externally, within 30 minutes. High severity, T1537 Transfer Data to Cloud Account.
  • Public on the web: any single file made public. Low on its own, worth a look during an incident.
  • Ownership transfer: change_owner to another account. Routine when people leave, notable during an incident.
  • External group member: an outside address added to a Google Group inherits the group's shared files and mail (Groups log add_user).

The analyzer's Entities → Drive files view lists downloads and sharing changes per file. External addresses lists every outside recipient with how it was seen: Drive share, group member, forwarding target.

Pattern 3: Google Takeout

Takeout exports a user's data (mail, Drive, contacts, calendar…) as downloadable archives. For an attacker holding a session, it is the one-click way to take everything. Google's Takeout log events record when an export starts, completes and is downloaded. The log is available in some editions only, and completion can lag by up to many days for large exports.

The analyzer treats any user Takeout start, schedule, completion or download as high severity (T1567) and shows the products requested and the destination. Admins can allow or block Takeout per organizational unit or group. For Workspace, it is allowed by default.

Pattern 4: an app does it

A third-party app with drive or drive.readonly scope can list and fetch every file the user can see. That produces OAuth token activity events, not necessarily Drive download events. If the OAuth review turns up a Drive-scoped app granted during the incident, scope its API activity.

Know your logging coverage first

Drive logging depends on licensing. In 2023, Mitiga reported that actions in a user's private drive were not logged for users on the free Cloud Identity license, only for paid Workspace licenses. Confirm what your editions record before you conclude "nothing was downloaded". The broader list of gaps is in audit log limitations.

Also remember:

  • The Drive log records that a file was downloaded, not what happened to it afterwards.
  • Viewing a document in the browser (view) and then copying its content leaves only the view.
  • Console exports cap at 100,000 rows. A month of org-wide Drive activity needs the Reports API.

Response

  1. Contain the account (reset sign-in cookies, revoke tokens) before anything else.
  2. Remove external shares and public links created in the incident window. Restore ownership where it moved.
  3. List the downloaded files for the legal and privacy assessment. Personal data may trigger notification duties.
  4. Restrict Takeout, external sharing defaults and unconfigured app access for sensitive units.

The fictional BEC walkthrough includes a 24-file overnight download from the attacker's IP. Try it in the analyzer with Try a sample.

FAQ

How do I see who downloaded files from Google Drive?

Open Reporting → Audit and investigation → Drive log events in the Admin console and filter on the Download event, or query the Reports API with applicationName=drive and eventName=download. Each record gives the actor, file title and ID, owner and IP address.

Is Google Takeout logged in Google Workspace?

Yes. Takeout log events record when a user starts a Takeout export, when it completes and when it is downloaded. Google documents that completion can lag by up to many days for large exports, and the Takeout log is available only in some editions.

Related articles

What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.
A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
Investigate a Google Workspace suspicious login: is_suspicious, hosting ASNs, new countries, impossible travel, failed-login bursts, 2SV and recovery changes.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.