Google Workspace Incident Response Checklist: First Hour
A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.
TL;DR. In the first hour: (1) export the evidence (audit logs and the mailbox's Gmail settings), (2) cut access (suspend or reset sign-in cookies, revoke OAuth tokens), (3) remove persistence (forwarding, filters, delegates, send-as, rogue apps), (4) reset the password and harden 2SV, (5) stop the money (call recipients of fraudulent mail, freeze changed payments). Then investigate with the pillar guide and the in-browser analyzer.
This is the list I want pinned on the wall when a finance mailbox looks compromised. It is deliberately short. Every item is either reversible or protects evidence. Where Google documents a step, the link goes to Google's own Admin Help. That is the authoritative source for where each setting lives in the Admin console, and those paths change over time.
Minute 0–10: preserve before you clean
Clean-up actions change state. Deleting a filter removes the only copy of its criteria. Revoking a token is logged, but the app's name and scopes stay easiest to read in the original grant. So first:
- Export the Login, OAuth token, User accounts and Gmail logs for the account, from 30 days before the suspicious email until now. See how to export Google Workspace audit logs. If time is short, the Admin console CSV export is the fastest route.
- Capture the mailbox's Gmail settings: filters, forwarding addresses, auto-forwarding, delegates, send-as. Use the Gmail API if you can, or screenshots of the user's Gmail settings pages if you can't.
- Write down what you do and when, in UTC. Your own actions will appear in the Admin log. You will need to tell them apart from the attacker's.
Why the hurry: Google keeps most audit log events for six months, and some events (OAuth tokens, Takeout completion) take hours to appear. Export now and again tomorrow.
Minute 10–25: cut the attacker's access
- Suspend the account if the attacker may still be active. It is the first step of Google's identify and secure compromised accounts procedure.
- Reset sign-in cookies. In the Admin console go to Directory → Users → the user → Security → Sign-in cookies → Reset. This signs the user out of browser sessions everywhere. It is how you evict an AiTM-stolen session. The API equivalent is
users.signOut. With a third-party IdP, also end the session at the IdP. - Revoke OAuth tokens of any app granted during the incident (the user → Security → Connected applications). Then block the app for the organization in Security → Access and data control → API controls → Manage third-party app access. See Google's app access control guide.
- Remove app passwords the account may have created. They bypass 2SV for legacy clients.
Minute 25–40: remove mailbox persistence
- Forwarding. Disable automatic forwarding and delete unknown forwarding addresses (Gmail settings → Forwarding and POP/IMAP). At org level, consider unticking Allow users to automatically forward email to another address under Apps → Google Workspace → Gmail → End User Access. See let users automatically forward their own Gmail.
- Filters. Delete filters that forward, archive, trash or mark as read anything about invoices, payments or bank details. Then restore what they hid: search All Mail and Trash for supplier and customer replies. Those messages are often the fraud evidence. Background: finding a hacker's Gmail forwarding rule.
- Delegates and send-as addresses the user doesn't recognise (Gmail settings → Accounts).
- Recovery email and phone. Check them with the user. Attackers change them to win the account back.
Minute 40–50: re-secure the identity
- Reset the password now, after the steps above rather than before, and require a change at next sign-in.
- Harden 2-step verification. Check 2SV is on. For finance users and admins, move to security keys or passkeys. Codes and phone prompts can be relayed by AiTM kits. Security keys can't. See Google's deploy 2-Step Verification and CISA's phishing-resistant MFA fact sheet.
- If an admin account is involved, review super admins, admin roles, SSO profiles and domain-wide delegation now. Details in admin role abuse and SSO changes.
Minute 50–60: stop the money
Business email compromise is a payment fraud before it is an IT problem.
- Phone the external recipients of any fraudulent "new bank details" message, on a number you already had. Don't reply by email.
- Freeze pending payments whose bank details changed recently, and ask your bank to recall any transfer already sent. The FBI's IC3 advises contacting the financial institution immediately to request a recall and filing a complaint at ic3.gov. Use your national equivalent outside the US.
- Tell finance to verify every bank detail change by phone for the next weeks.
After the first hour
Now you have time to investigate properly:
- Drop the exports into the Google Workspace audit log analyzer. It flags the sign-in, persistence and collection events, builds a timeline and turns findings into a remediation list in this same order.
- Follow the method in the investigation guide to scope what was read or downloaded.
- Check the other mailboxes that received the phishing email. AiTM campaigns rarely target one person.
Common mistakes
| Mistake | Why it hurts |
|---|---|
| Resetting the password first and calling it done | OAuth tokens, forwarding and filters keep working |
| Deleting filters before recording them | You lose the attacker's keywords and destination address |
| Waiting days to export | Retention is finite, and every day pushes the start of the incident closer to the edge |
| Only checking the victim's mailbox | Admin-level routing or compliance rules can copy mail for everyone |
| Emailing suppliers about the fraud | The attacker may still read or intercept the thread |
FAQ
Should I suspend a compromised Google Workspace account?
If the attacker may still be active, yes. Suspension is the first step in Google's own guidance for compromised accounts. It blocks access while you work. Export the logs and Gmail settings first, or right after, so that the clean-up does not destroy evidence you still need.
In what order should I reset the password and revoke tokens?
Revoke sessions and OAuth tokens and remove forwarding and filters first, then reset the password. Resetting the password alone leaves third-party app tokens, forwarding and filters working.