Webinar: How malicious OAuth apps can lead to Google Workspace breaches
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords.

Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...] Google Workspace attackers don't necessarily need to exploit a software vulnerability or steal a user's password to gain access to an organization's data. On September 23, 2026, BleepingComputer will host a live webinar titled " Breach autopsy: How fast-growing companies are breached through Google Workspace " with Material Security.
The resulting access depends on the permissions granted, but the attack demonstrates why organizations need visibility into third-party applications and the access users are allowed to authorize. By examining two attacks that combined malicious OAuth applications with social engineering, this webinar will provide a practical look at how these breaches happen and what defenders can do to reduce their exposure.
A user may believe they are connecting a legitimate application or responding to a trusted request while actually granting a malicious app permissions within their Google Workspace environment.
Who is affected
While this makes it easier to connect legitimate applications to Google Workspace, attackers can also abuse the authorization process by convincing users to grant permissions to malicious apps.
Rather than stealing credentials, attackers can use social engineering to persuade a target to authorize an application, potentially providing access to sensitive information available through the permissions the user approved.
These attacks highlight why protecting Google Workspace requires organizations to look beyond passwords and traditional authentication controls and understand which applications have access to their environment.
During the webinar, the speakers will break down how the two attacks unfolded, the weaknesses that allowed them to succeed, and the decisions organizations made during the critical first hours of the incidents.
Attendees will also learn which security controls provide the greatest value for fast-growing organizations and what the speakers would prioritize if they were building a Google Workspace security program from scratch.
Malicious OAuth apps provide attackers with another approach: convincing the victim to authorize access instead.
Why this matters
The resulting access depends on the permissions granted, but the attack demonstrates why organizations need visibility into third-party applications and the access users are allowed to authorize.
By examining two attacks that combined malicious OAuth applications with social engineering, this webinar will provide a practical look at how these breaches happen and what defenders can do to reduce their exposure.
The technical picture
A user may believe they are connecting a legitimate application or responding to a trusted request while actually granting a malicious app permissions within their Google Workspace environment.
What remains unknown
The available reporting does not establish whether the issue is being actively exploited in the wild.
The available reporting does not establish who is behind the activity, if an attacker is involved.