Google response (from Jan): "Our security systems automatically lock an employee’s corporate account when they detect that the account is at risk of compromise due to credential problems or when an automated rule involving the handling of sensitive data has been triggered. In this instance, yesterday our systems detected that an account had exfiltrated thousands of files and shared them with multiple external account…
how would this system detect sharing with external accounts? sounds like they put some words together to make it sound like it’s all standardized and automated and not result of human actions
All outgoing email is being scanned for sensitive information in plain text or attachments. This is standard practice in every corporation and something you are being warned about when being on-boarded as a new-joiner.