This video talks about a couple potential vulnerabilities that can be used in gsuite apps for social engineering attacks.
You can add invites without sending an email – adding a potential attack vector and then phish accounts, even if they have 2fa enabled.