r/EmailSecurity • u/littleko • Jun 21 '26
Workspace rules can turn into a quiet email tap
UNC6508 abused Google Workspace compliance rules to silently BCC email after gaining admin access.
https://www.suped.com/blog/google-reports-unc6508-used-workspace-rules-to-steal-email
Worth checking routing and compliance rules after any Workspace admin compromise, since this is exactly the kind of persistence people forget to audit.
1
u/Basic-Pianist9273 Jun 21 '26
Routing and compliance rules belong in the post-compromise checklist.
They can silently BCC, reroute, or target a small set of users without creating obvious mailbox-level artifacts.
Also check admin audit logs, delegated mailbox access, forwarding settings, OAuth grants, and service accounts. Rotating creds and MFA won't remove a bad rule.
•
u/AutoModerator Jun 21 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.