Our enterprise recently dealt with a coordinated campaign in which attackers used adversary-in-the-middle (AiTM) phishing proxies to compromise accounts in legitimate Google Workspace tenants. Compromised mailboxes then appeared to automate additional phishing, creating a self-propagating cycle across organizations. Has anyone else seen similar activity, and what containment measures have worked?
The most effective steps for us were contacting Google Workspace support immediately, shortening session lifetimes, enforcing two-step verification with "trust this device" disabled, revoking OAuth tokens, signing out active sessions, resetting passwords promptly, and repeatedly checking Workspace logs and security reports for renewed activity. We also found it important to preserve tenant reporting before making broad remediation changes and to review account, login, OAuth, and email activity continuously.
We are also investigating whether malicious calendar invitations are bypassing normal email-spam controls and exposing users to phishing links. Any practical guidance for breaking the propagation cycle and preventing reinfection would be appreciated.
4 Answers
Move quickly with Google Workspace support and preserve evidence before making large-scale changes. Use the investigation and audit tools to identify suspicious logins, OAuth applications, forwarding rules, newly added delegates, mailbox changes, and related messages. Then apply containment consistently across the tenant and continue checking for flare-ups; resetting one account is not enough if tokens or other accounts remain compromised.
The “worm” appears to be an automated phishing loop rather than a traditional malware worm. Attackers compromise one account, use it to send convincing phishing messages to other Workspace users, steal authenticated sessions through an AiTM proxy, and then use each newly compromised account to continue the campaign. That can make the activity spread rapidly between otherwise unrelated organizations.
Calendar invitations deserve special attention. In some configurations, malicious invites can appear on a user’s calendar even when the related message is filtered as spam, and the event description may contain the phishing link. Review the organization’s Google Calendar invitation controls and consider allowing invitations only from users who have received an email response. Also warn users not to trust calendar events simply because they appear in the calendar.
Shortening sessions and disabling trusted devices may reduce persistence, but they do not reliably defeat an AiTM attack because the attacker can capture the authenticated session during the phishing flow. Strong phishing-resistant, passwordless authentication—such as security keys or passkeys—is a better long-term defense. During an incident, revoke OAuth grants and active sessions, reset affected credentials, review account and forwarding settings, and monitor login and audit logs closely.

That matches what we observed: once several accounts were compromised, the volume increased quickly and the messages appeared to come from legitimate tenant users.