Google Workspace Under Login Attack: What to Do

A one-page playbook for small and mid-size organizations

Failed logins are normal background noise on the internet. The real question is whether any are succeeding, and whether your accounts are protected if one does.

Step 1: Check if anything got in

Sign in to admin.google.com and go to Reporting > Audit and investigation > Login audit log. Filter for successful logins in the last 30 days. Look for logins from countries no one works in, unfamiliar IP addresses, or dormant accounts.

If you find a suspicious successful login, suspend the account, reset the password, sign out all sessions, and check the user's Gmail for new forwarding rules or filters.

Step 2: Audit your 2FA coverage

Go to Reporting > User reports > Security. This shows you who has 2-Step Authentication (2FA) turned on and who does not. Immediately add 2FA to all accounts without it.

Step 3: Close the biggest gaps, in order

Step 4: Turn on alerts so you find out faster next time

Path: Security > Alert center > Settings. Enable alerts for suspicious logins, leaked passwords, and changed email settings. Route them to an inbox or channel someone actually reads.

If you do only one thing: enforce 2-Step Verification for everyone. It is the single highest-impact change you can make.


Revision #1
Created 14 May 2026 02:22:27 by Josh
Updated 14 May 2026 02:26:42 by Josh