Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails
Brief
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails.
The messages can look ordinary because they come from real organizational domains, not newly created addresses often flagged by filters. That makes a familiar inbox channel harder to trust and easier to misuse.
The activity is especially concerning for schools, colleges, and education organizations. A stolen account gives criminals a credible sender identity, mailing habits, and a domain reputation. Recipients may open a message that appears to come from a known institution.
Spamhaus said in a report shared with Cyber Security News (CSN) that it had observed the same target domain across multiple spam campaigns.
The researchers identified more than 450 compromised education domains using Google Workspace, while stressing that the activity is not limited to education.
