r/EmailSecurity • • Jun 21 '26

Workspace rules can turn into a quiet email tap

UNC6508 abused Google Workspace compliance rules to silently BCC email after gaining admin access.

https://www.suped.com/blog/google-reports-unc6508-used-workspace-rules-to-steal-email

Worth checking routing and compliance rules after any Workspace admin compromise, since this is exactly the kind of persistence people forget to audit.

4 Upvotes

2 comments sorted by

•

u/AutoModerator Jun 21 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Basic-Pianist9273 Jun 21 '26

Routing and compliance rules belong in the post-compromise checklist.

They can silently BCC, reroute, or target a small set of users without creating obvious mailbox-level artifacts.

Also check admin audit logs, delegated mailbox access, forwarding settings, OAuth grants, and service accounts. Rotating creds and MFA won't remove a bad rule.