What is a suspicious-login alert?¶
A suspicious-login alert is a provider's recorded assessment that an authentication or session had unusual characteristics or matched a risk signal. The alert explains what the provider suspected; the underlying login and resulting session records explain what the service accepted and what happened next.
One alert usually points to several records¶
Google Workspace records a successful login for Dave's account at 07:26 and marks it suspicious. Dave receives a notification at 07:28 and reports that he does not recognise the login. At 07:31, a session created by the login changes a recovery setting.
Preserve the reason, outcome and consequence¶
Keep the exact alert text, provider event and risk identifiers, generation time, account, success/failure/challenge outcome, authentication method, application, device and network. Then preserve any session created, the resource or security events it produced, and the user or administrator response.
An alert can be generated before, during or after the provider decision. A blocked attempt, a challenged attempt and a successful login have different evidential meanings. The next comparison is the provider's risk detail, the known device and normal pattern, the person's response, and the activity attached to any accepted session.
Unusual-location alerts deal with one location-based interpretation. Recognising unauthorised access explains how alert, session, resource and independent evidence can converge.
Current Google Workspace example - checked 2 September 2026
Google Workspace currently documents the login-audit event suspicious_login. Its Reports API can return successful login events filtered with is_suspicious==true; the login audit includes separate event definitions and parameters rather than one universal “suspicious login” record.
Record coverage and retention vary. Google's current Login Activity Report also notes that it covers explicit password and SAML single sign-on logins, so absence from that report should not be generalised to every session route.
The point to remember
A suspicious-login alert records a provider assessment. Join it to the actual login decision, user response and resulting session activity before deciding whether compromise occurred.