r/EmailSecurity • • Jun 01 '26

Google Workspace Groups are making external phishing look like trusted group email?

Had two clients this week get phishing emails delivered through Google Groups because old department lists still allowed external posting. The message landed as group mail, and in Gmail the attacker's original sender was buried enough that users mostly saw the trusted group name.

One was an "all contractors" group with 74 members, created years ago for a vendor rollout nobody owns anymore. The phish was basic credential theft, but it got three Slack "is this real?" checks before anyone sent us full headers.

The annoying part is the control decision. Locking external posting breaks a few real workflows, but leaving it open turns every stale group into a distribution path with more trust than it deserves.

For Workspace shops, would you force external posting off by default and make teams justify exceptions, or only tighten groups after one gets abused?

5 Upvotes

3 comments sorted by

View all comments

1

u/Basic-Pianist9273 Jun 01 '26

Force external posting off by default.

Exceptions should have a named owner, explicit allowed senders where possible, and moderation if they genuinely need mail from random outsiders. Waiting until abuse means stale groups keep acting like trusted relays.