Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Google Workspace BEC Investigation Example (Fictional Case)

A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.

Published on 6 min read

TL;DR. This walkthrough uses the analyzer's built-in sample, a fictional incident at an invented company ("Northbridge Supplies", .example domains, documentation-range IP addresses). Over two days, the finance lead's session is hijacked from a DigitalOcean IP. A "PDF Viewer Pro" app gets full Gmail access. A filter forwards and hides every invoice. 24 Drive files are downloaded overnight. A "new bank details" email goes to two customers. The logs show all of it. Click Try a sample on the home page to follow along.

Fictional scenario. Northbridge Supplies, its staff, suppliers, customers and every address and IP below are invented. The files use the real export formats (Reports API JSON, Admin console CSV, Gmail API settings) and were generated for demonstration only.

The call

Thursday 17 September 2026, mid-morning. The accounts-payable contact at a customer, Hartwell Retail, calls Northbridge's finance lead, Claire Martin. She wants to confirm the "updated bank details" received that morning before she changes the supplier record. Claire never sent it. IT exports the logs for the week and opens the analyzer.

Evidence collected

FileFormatLog
login_activities.jsonReports APILogin
user_accounts_activities.jsonReports APIUser accounts
token_activities.jsonReports APIOAuth token
gmail_activities.jsonReports APIGmail
drive_log_events.csvAdmin console CSVDrive
admin_log_events.csvAdmin console CSVAdmin
gmail-settings/claire.martin@…/filters.json, forwardingAddresses.json, autoForwarding.jsonGmail APIMailbox settings

The coverage panel shows seven log sources from 7 to 18 September and no missing source. That matters: a "clean" or "compromised" verdict here is based on every persistence mechanism the tool checks.

Verdict: Compromised

The top finding is the critical chain "Account takeover pattern: risky sign-in followed by mailbox persistence" for claire.martin@northbridge.example. It links ten findings. The rest of this post rebuilds the timeline from them. All times are UTC.

Timeline

Time (UTC)LogEventReading
15 Sep 06:40Loginlogin_success from the office IP (FR)Normal start of day
15 Sep 06:47GmailReceive: "Invoice INV-20931 awaiting your signature" from a look-alike e-signature senderThe lure
15 Sep 06:52GmailLink click on the same messageClaire opens the phishing page
15 Sep 06:53Loginlogin_verification (Google prompt passed) then login_success from 203.0.113.45, AS14061 DigitalOcean, USAiTM relay: password and prompt proxied from a VPS
15 Sep 06:57OAuth tokenauthorize "PDF Viewer Pro", scopes https://mail.google.com/, gmail.settings.basicIllicit consent grant from the attacker's IP
15 Sep 07:00–07:30OAuth token64 activity events: messages.list, messages.get, one settings.filters.createMailbox read via the API, filter created by the app
15 Sep 07:04User accountsemail_forwarding_out_of_domain → c.martin.finance@mailbox-relay.exampleExternal forwarding address added
undatedGmail settingsFilter invoice OR payment OR remittance OR "bank details" → remove INBOX and UNREAD, forward to the same addressEmail hiding rule plus forward
15–17 SepGmailThree supplier invoices received, auto-forwarded to the relay address and archivedClaire never sees them
16 Sep 00:07Loginlogin_success from 203.0.113.46 (same ASN)Second attacker session, at night
16 Sep 00:10–00:16Drive24 download events in six minutes: supplier bank details, payroll, customer master data…Mass download
17 Sep 08:12GmailSend: "Updated bank details for Northbridge Supplies invoices" to two external customer addresses, from the attacker IPThe fraud
17 Sep 08:12GmailThe sent message is moved to trashCovering tracks

Findings, one by one

Finding (severity)What it caughtATT&CK
Successful login from a hosting / VPS network (high)Two sign-ins from AS14061T1078.004, T1557
Impossible travel (high)FR office at 06:40, US at 06:53T1078.004
New country for this user (medium)First US sign-in after a French baselineT1078.004
Third-party app granted access to Gmail (high)"PDF Viewer Pro" with https://mail.google.com/T1528, T1114.002
App reading Gmail through the API at volume (medium)64 calls in 30 minT1114.002
Automatic forwarding to an external address (high)email_forwarding_out_of_domainT1114.003
Gmail filter forwards mail outside (high)Filter forward to the relay addressT1114.003
Gmail filter hides finance mail (high)-INBOX -UNREAD on invoice/payment wordsT1564.008
Messages auto-forwarded (medium)Three supplier invoicesT1114.003
Finance messages trashed or archived in bulk (medium)Invoices archived, fraud mail trashedT1564.008, T1070.008
Outgoing mail about changed bank details (medium)Sent to two external customersT1656, T1534
Mass download of Drive files (high)24 files in 6 min from the attacker IPT1530
Admin reset a user's password / User created (low)IT created a new hire's account on 9 SepT1098, T1136.003

The two low admin findings are the false positives of this case. The IT admin created lucas.moreau@… and set his password from the office IP, a week before the incident. Checked with IT and matched to an HR request: closed. That is the right way to handle low findings. Explain them, don't ignore them.

What the analyst concludes

  1. Initial access: AiTM phishing. The password and the Google prompt were relayed, which is why 2SV didn't stop it. Remediation includes moving finance to security keys (why).
  2. Persistence: three independent mechanisms (OAuth token, forwarding address, filter). A password reset alone would have removed none of them. More in Gmail forwarding rules and suspicious OAuth apps.
  3. Impact: supplier invoices intercepted for three days, 24 sensitive files downloaded, a fraudulent bank-change email sent to two customers.
  4. No evidence of admin-level compromise: no role, SSO, delegation or routing changes in the Admin log for the period.

Remediation, in the tool's order

Contain the session (reset sign-in cookies) → reset the password → enforce phishing-resistant 2SV → remove forwarding → delete the filter and restore the hidden invoices → revoke "PDF Viewer Pro" and block its client ID → review admins → review Drive sharing → phone Hartwell Retail and Corvin Foods → freeze payments with changed details → preserve the logs → block the attacker's IPs.

What this sample doesn't show

Real cases are messier: CSV exports without network columns, several victims, legitimate VPN users, apps that are both popular and over-scoped. The sample is small (about 430 events) and has a single victim. Treat it as a map of where evidence sits, not as a template for how obvious a real incident will be. See audit log limitations for the gaps you will meet.

To run the same analysis on your own tenant, follow the step-by-step guide.

Related articles

How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.
What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.
A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.