Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails.
The messages can look ordinary because they come from real organizational domains, not newly created addresses often flagged by filters. That makes a familiar inbox channel harder to trust and easier to misuse.
The activity is especially concerning for schools, colleges, and education organizations. A stolen account gives criminals a credible sender identity, mailing habits, and a domain reputation. Recipients may open a message that appears to come from a known institution.
Spamhaus said in a report shared with Cyber Security News (CSN) that it had observed the same target domain across multiple spam campaigns.
The researchers identified more than 450 compromised education domains using Google Workspace, while stressing that the activity is not limited to education.
The campaign shows how account compromise can amplify email fraud. Instead of relying only on spoofed addresses, attackers can send from a legitimate environment and blend into routine conversations.
The immediate risk is credential theft or payment fraud, while the compromised mailbox damages trust in the organization being impersonated.
Hackers Leveraging GoogleWorkspace Accounts
The reported operation does not describe a single malware family or a fixed phishing template. Its common thread is the abuse of genuine Google Workspace accounts after takeover.
That distinction matters: the account becomes the delivery mechanism, allowing criminals to distribute deceptive content from domains that recipients and security systems recognize.
Spamhaus did not publish the initial access method, message contents, or the full list of affected domains in the supplied material.
Organizations should not assume that one subject line, attachment type, or lure defines the threat. Any unexpected request for a sign-in, payment, document review, or account action warrants independent verification.
Trusted services have repeatedly been used to lend weight to malicious messages. In one recent Google-themed credential phishing campaign, attackers used familiar sign-in branding and redirect chains to lead recipients to a credential-stealing page.
It reinforces a lesson: a recognizable sender or platform is evidence to examine, not proof that a message is safe.
Education organizations face particular pressure because their domains serve changing groups of staff, students, parents, alumni, and partners.
Busy academic periods create a steady flow of notices and shared files. A message imitating a routine administrative request can be convincing when it reaches someone from an authentic institutional account.
Protecting Accounts and Recipients
Administrators should focus on stopping account takeover and limiting its reach.
Require multi-factor authentication for every Workspace account, remove legacy access paths where possible, and review recovery methods, forwarding rules, connected applications, and administrator privileges.
Suspicious sign-ins or new mail rules should trigger a prompt investigation, particularly on accounts that send mail to large groups.
Mail teams should watch for unusual sending volumes, unfamiliar recipients, repeated links, abrupt changes in message language, and logins from unexpected locations or devices.
They should make it simple for users to report suspicious mail. Guidance from the education sector threat trends emphasizes training faculty and staff to recognize targeted phishing, a useful safeguard when identities are abused.
Recipients should slow down before responding to requests involving passwords, money, files, or account changes.
Rather than replying or using the message’s links, they can confirm the request through a known phone number, saved contact, or portal. The email fraud safety guide also recommends checking the sender address and verifying links before clicking.
If an account is suspected of sending scams, organizations should reset credentials, revoke active sessions, inspect mailbox rules and authorized apps, preserve relevant logs, and alert likely recipients quickly.
Reviewing prior mail activity can identify recipients and reveal whether other accounts show the same signs. The response should include a calm warning that legitimate-looking email can still be malicious.
The key point is not to treat this as a problem confined to one provider or sector. The Google Classroom phishing incident showed how abuse of a legitimate education-related service can reach thousands of organizations.
Defenders need layered checks around identity, email behavior, and user verification so one compromised account does not become a broad scam platform.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world






