Business email is often the fastest path into everything else. A compromised Gmail or Google Workspace account can expose files, reset other SaaS accounts, change recovery settings and support payment fraud.
What you'll learn
- How to recognize a potentially compromised Google account.
- What an administrator should check after suspicious activity.
- Why sessions, OAuth tokens, forwarding rules and recovery methods matter.
- How to separate a Gmail problem from a broader identity compromise.
Current watch item
What should you check?
- Review unfamiliar sign-ins and recent security activity.
- Verify recovery email, phone and multi-factor authentication methods.
- Check Gmail forwarding, filters and delegated access for unauthorized changes.
- Review third-party OAuth applications and connected services.
- If a Workspace user is suspected compromised, use administrator controls to contain access before restoring normal use.
- Review Admin audit logs if an administrator account is involved.
What not to do
- Do not only change the password and assume every active session or OAuth grant is gone.
- Do not ignore suspicious forwarding rules or mailbox delegates.
- Do not use the same compromised email account to reset every other business system before securing it.
- Do not delete evidence such as phishing messages or security alerts before documenting them.
Official sources CompFlorida reviewed
Google Account Help guidance for hacked/compromised accounts and Google Workspace Admin guidance for identifying and securing compromised users.
What you should know when you're finished
You should know whether this technology is current, who owns its security and recovery settings, what needs attention now, and whether an issue belongs to the product, the account, the device, the network, or another dependency.
← Back to Technology Risk Center
Last reviewed: September 22, 2026. This resource is educational and does not replace the vendor's current advisory or a review of your specific environment.

