Google Workspace BEC Investigation Example (Fictional Case)
A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
TL;DR. This walkthrough uses the analyzer's built-in sample, a fictional incident at an invented company ("Northbridge Supplies", .example domains, documentation-range IP addresses). Over two days, the finance lead's session is hijacked from a DigitalOcean IP. A "PDF Viewer Pro" app gets full Gmail access. A filter forwards and hides every invoice. 24 Drive files are downloaded overnight. A "new bank details" email goes to two customers. The logs show all of it. Click Try a sample on the home page to follow along.
Fictional scenario. Northbridge Supplies, its staff, suppliers, customers and every address and IP below are invented. The files use the real export formats (Reports API JSON, Admin console CSV, Gmail API settings) and were generated for demonstration only.
The call
Thursday 17 September 2026, mid-morning. The accounts-payable contact at a customer, Hartwell Retail, calls Northbridge's finance lead, Claire Martin. She wants to confirm the "updated bank details" received that morning before she changes the supplier record. Claire never sent it. IT exports the logs for the week and opens the analyzer.
Evidence collected
| File | Format | Log |
|---|---|---|
login_activities.json | Reports API | Login |
user_accounts_activities.json | Reports API | User accounts |
token_activities.json | Reports API | OAuth token |
gmail_activities.json | Reports API | Gmail |
drive_log_events.csv | Admin console CSV | Drive |
admin_log_events.csv | Admin console CSV | Admin |
gmail-settings/claire.martin@…/filters.json, forwardingAddresses.json, autoForwarding.json | Gmail API | Mailbox settings |
The coverage panel shows seven log sources from 7 to 18 September and no missing source. That matters: a "clean" or "compromised" verdict here is based on every persistence mechanism the tool checks.
Verdict: Compromised
The top finding is the critical chain "Account takeover pattern: risky sign-in followed by mailbox persistence" for claire.martin@northbridge.example. It links ten findings. The rest of this post rebuilds the timeline from them. All times are UTC.
Timeline
| Time (UTC) | Log | Event | Reading |
|---|---|---|---|
| 15 Sep 06:40 | Login | login_success from the office IP (FR) | Normal start of day |
| 15 Sep 06:47 | Gmail | Receive: "Invoice INV-20931 awaiting your signature" from a look-alike e-signature sender | The lure |
| 15 Sep 06:52 | Gmail | Link click on the same message | Claire opens the phishing page |
| 15 Sep 06:53 | Login | login_verification (Google prompt passed) then login_success from 203.0.113.45, AS14061 DigitalOcean, US | AiTM relay: password and prompt proxied from a VPS |
| 15 Sep 06:57 | OAuth token | authorize "PDF Viewer Pro", scopes https://mail.google.com/, gmail.settings.basic | Illicit consent grant from the attacker's IP |
| 15 Sep 07:00–07:30 | OAuth token | 64 activity events: messages.list, messages.get, one settings.filters.create | Mailbox read via the API, filter created by the app |
| 15 Sep 07:04 | User accounts | email_forwarding_out_of_domain → c.martin.finance@mailbox-relay.example | External forwarding address added |
| undated | Gmail settings | Filter invoice OR payment OR remittance OR "bank details" → remove INBOX and UNREAD, forward to the same address | Email hiding rule plus forward |
| 15–17 Sep | Gmail | Three supplier invoices received, auto-forwarded to the relay address and archived | Claire never sees them |
| 16 Sep 00:07 | Login | login_success from 203.0.113.46 (same ASN) | Second attacker session, at night |
| 16 Sep 00:10–00:16 | Drive | 24 download events in six minutes: supplier bank details, payroll, customer master data… | Mass download |
| 17 Sep 08:12 | Gmail | Send: "Updated bank details for Northbridge Supplies invoices" to two external customer addresses, from the attacker IP | The fraud |
| 17 Sep 08:12 | Gmail | The sent message is moved to trash | Covering tracks |
Findings, one by one
| Finding (severity) | What it caught | ATT&CK |
|---|---|---|
| Successful login from a hosting / VPS network (high) | Two sign-ins from AS14061 | T1078.004, T1557 |
| Impossible travel (high) | FR office at 06:40, US at 06:53 | T1078.004 |
| New country for this user (medium) | First US sign-in after a French baseline | T1078.004 |
| Third-party app granted access to Gmail (high) | "PDF Viewer Pro" with https://mail.google.com/ | T1528, T1114.002 |
| App reading Gmail through the API at volume (medium) | 64 calls in 30 min | T1114.002 |
| Automatic forwarding to an external address (high) | email_forwarding_out_of_domain | T1114.003 |
| Gmail filter forwards mail outside (high) | Filter forward to the relay address | T1114.003 |
| Gmail filter hides finance mail (high) | -INBOX -UNREAD on invoice/payment words | T1564.008 |
| Messages auto-forwarded (medium) | Three supplier invoices | T1114.003 |
| Finance messages trashed or archived in bulk (medium) | Invoices archived, fraud mail trashed | T1564.008, T1070.008 |
| Outgoing mail about changed bank details (medium) | Sent to two external customers | T1656, T1534 |
| Mass download of Drive files (high) | 24 files in 6 min from the attacker IP | T1530 |
| Admin reset a user's password / User created (low) | IT created a new hire's account on 9 Sep | T1098, T1136.003 |
The two low admin findings are the false positives of this case. The IT admin created lucas.moreau@… and set his password from the office IP, a week before the incident. Checked with IT and matched to an HR request: closed. That is the right way to handle low findings. Explain them, don't ignore them.
What the analyst concludes
- Initial access: AiTM phishing. The password and the Google prompt were relayed, which is why 2SV didn't stop it. Remediation includes moving finance to security keys (why).
- Persistence: three independent mechanisms (OAuth token, forwarding address, filter). A password reset alone would have removed none of them. More in Gmail forwarding rules and suspicious OAuth apps.
- Impact: supplier invoices intercepted for three days, 24 sensitive files downloaded, a fraudulent bank-change email sent to two customers.
- No evidence of admin-level compromise: no role, SSO, delegation or routing changes in the Admin log for the period.
Remediation, in the tool's order
Contain the session (reset sign-in cookies) → reset the password → enforce phishing-resistant 2SV → remove forwarding → delete the filter and restore the hidden invoices → revoke "PDF Viewer Pro" and block its client ID → review admins → review Drive sharing → phone Hartwell Retail and Corvin Foods → freeze payments with changed details → preserve the logs → block the attacker's IPs.
What this sample doesn't show
Real cases are messier: CSV exports without network columns, several victims, legitimate VPN users, apps that are both popular and over-scoped. The sample is small (about 430 events) and has a single victim. Treat it as a map of where evidence sits, not as a template for how obvious a real incident will be. See audit log limitations for the gaps you will meet.
To run the same analysis on your own tenant, follow the step-by-step guide.