Does an unusual-location alert prove compromise?¶
No. It proves that a provider recorded an alert or risk assessment about the apparent location of an account event. Compromise becomes stronger when the underlying session, device, authentication and later activity also conflict with an authorised explanation.
Dave's hotel login needs context¶
Dave signs in to Google Workspace from a Lisbon hotel at 19:42 using his usual Pixel phone. Google records the successful login and marks it suspicious because the context differs from Dave's normal pattern. The alert is genuine, but Dave's travel booking, known device and ordinary Drive activity may support legitimate use.
Test the event that caused the alert¶
Retain the provider's exact wording, risk level and alert/event identifiers, plus the underlying sign-in time, IP address, device, application, authentication method, outcome and session. Location commonly comes from IP-based estimation and may describe a network exit rather than the user.
Then inspect what followed. A new device, denied MFA prompt, recovery change and bulk download form a very different sequence from a known device performing ordinary work during confirmed travel. The next useful records are therefore the device and session history, the account's normal network use, relevant travel or business records and the resource events after authentication.
Absence of an alert is equally narrow. A reused session token, familiar device or nearby network may appear ordinary. Impossible-travel detection explains one particular comparison algorithm; an “unusual location” label may use a different model.
Current Google Workspace example - checked 2 September 2026
Google Workspace currently documents a suspicious_login login-audit event for a login it assesses as suspicious. Its administrator guidance says unusual location or behaviour outside a user's normal pattern may contribute to that assessment. The login audit can also expose successful logins with an is_suspicious parameter.
Alert wording, accessible fields and detection logic can change. Preserve the alert and export the underlying activity rather than relying on a screenshot or colour alone.
The durable principle¶
A provider alert is evidence of the provider's assessment. Independent session, device and activity records decide how much weight that assessment carries for compromise.
The point to remember
State the alert positively but narrowly: the provider identified unusual location context. Test who controlled the session through device, authentication, travel and subsequent activity.