CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 408

As cited

Copy frozen at (site build).

breaches incidents

Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts

Kaspersky Lab researchers identified a new attack toolkit used by the ToddyCat group to compromise corporate Gmail accounts. The toolkit enables attackers to access accounts through an API, read email conversations, and extract data from calendars and other Google services while evading detection.

Why it matters: Organizations using Gmail for corporate email face risk of account compromise and data exfiltration by a sophisticated threat actor, requiring immediate review of Gmail API access logs and account security controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts

Kaspersky Lab researchers identified a toolkit used by the ToddyCat threat group that enables attackers to compromise corporate Gmail accounts through the Google application programming interface (API). The toolkit allows adversaries to access mailboxes, collect calendar data, and exfiltrate information from linked Google services while remaining undetected for extended periods.

Why it matters: Organizations that use corporate Gmail accounts are at risk of silent data theft via abused API tokens and should immediately review OAuth permissions and monitor for anomalous API activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts

Kaspersky Lab researchers identified a toolkit used by the ToddyCat threat group that enables attackers to compromise corporate Gmail accounts through the Google application programming interface (API). The toolkit allows adversaries to access mailboxes, collect calendar data, and exfiltrate information from linked Google services while remaining undetected for extended periods.

Why it matters: Organizations that use corporate Gmail accounts are at risk of silent data theft via abused API tokens and should immediately review OAuth permissions and monitor for anomalous API activity.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary