Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts
Kaspersky Lab has identified a new toolkit used by the threat actor group ToddyCat that targets corporate Gmail accounts through API-based access, allowing attackers to read emails, extract calendar data, and move through connected Google services while staying hidden for long periods.
Why this matters: Corporate Gmail is not just email. It is calendars, shared documents, meeting notes, and contact histories — a detailed map of how an organization actually works. API-based access is the quiet kind of intrusion: no password reset, no obvious sign-in, nothing that triggers a standard alert. The people whose data gets read may never know it happened. If your company runs on Google Workspace, this is a reminder that account access and API permissions deserve the same scrutiny as your firewall.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.