Full Report
A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Unauthorized Access to Park West Psychology Google Workspace
## Executive Summary
Park West Psychology experienced a data breach involving unauthorized access to a Google Workspace account, resulting in the export of contact information. The incident was detected on June 15, 2026, when an unrecognized device was found registered to the account. While sensitive medical or financial data was not compromised, the exposure of names and email addresses has increased the risk of targeted phishing for affected individuals.
## Incident Details
- **Discovery Date:** June 15, 2026
- **Incident Date:** Occurred prior to or on June 15, 2026 (Reported July 15, 2026)
- **Affected Organization:** Park West Psychology (parkwestpsychology[.]com)
- **Sector:** Healthcare / Mental Health Services
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Identified June 15, 2026
- **Vector:** Account Takeover (ATO)
- **Details:** An unauthorized third party gained access to a corporate Google Workspace Gmail account.
### Lateral Movement
- **Details:** The attacker registered an unauthorized Windows device to the compromised Gmail account to maintain access and facilitate data movement.
### Data Exfiltration/Impact
- **Details:** The unauthorized party exported Google-generated contact data. The scope was limited to names and email addresses.
### Detection & Response
- **Discovery:** The incident was discovered during a security review or alert when an unrecognized Windows device was identified as being linked to the organization's account.
- **Response:** The compromised account was contained and secured on the same day it was discovered (June 15, 2026).
## Attack Methodology
- **Initial Access:** Unauthorized access to a Google Workspace account (likely via credential stuffing or phishing).
- **Persistence:** Registration of an unrecognized Windows device to the Gmail account.
- **Privilege Escalation:** Not disclosed; assumed access to the user's standard permissions.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Unknown third-party source.
- **Discovery:** Review of registered account devices.
- **Lateral Movement:** Limited to the Google Workspace environment.
- **Collection:** Aggregation of contact lists.
- **Exfiltration:** Export of contact data (Names/Emails).
- **Impact:** Medium; potential for downstream social engineering.
## Impact Assessment
- **Financial:** Not disclosed; costs associated with breach notification and remediation.
- **Data Breach:** Exposure of names and email addresses. No Social Security numbers or financial records were accessed.
- **Operational:** Limited; the account was contained quickly on the day of discovery.
- **Reputational:** Medium; concerns regarding the privacy of individuals associated with a psychology practice.
## Indicators of Compromise
- **Network indicators:** N/A
- **File indicators:** N/A
- **Behavioral indicators:** Unrecognized Windows device registration to a Google Workspace account; unauthorized data export activity.
## Response Actions
- **Containment:** The affected Google account was secured and unauthorized access was terminated on June 15, 2026.
- **Eradication:** Removal of the unauthorized Windows device from the account environment.
- **Recovery:** Public disclosure and reporting on July 15, 2026; notification to affected individuals.
## Lessons Learned
- **Visibility:** Identifying the unauthorized device registration was critical for discovery; however, the attacker was able to export data before detection.
- **MFA Vulnerability:** The incident underscores the importance of phishing-resistant MFA to prevent account takeovers.
## Recommendations
- **MFA:** Enforce hardware security keys (FIDO2) or authenticator apps across all Google Workspace accounts.
- **Audit Logs:** Regularly audit Google Workspace login logs and third-party app/device permissions.
- **Attack Surface Management:** Implement continuous monitoring to identify shadow IT and unauthorized hardware connecting to corporate resources.
- **Training:** Educate staff and patients on the risks of targeted phishing attempts following the breach.