We've had a lot of clients hit by this phishing attempt today. Some people at one of our security service vendors were even hit, which just goes to show you no one is immune to these types of attacks. Google services for businesses (G Suite) is such a behemoth and in many cases is the "budget" solution. In our experience, being a behemoth means they are a large target. In our experience, the budget solution means they devote a lot fewer employees and a lot less money in protecting their clients and users, compared to their competition. If you are forced to use G Suite or other business solutions from Google, (or even just Gmail for your personal email) your best protection is enabling 2 factor authentication, followed by using password best practices that we have previously written about.
More on multi-factor
Following up on our post the other day regarding the Yahoo! breach, security company Avast-AVG, one of our partners, is offering the same advice we offer, namely, you should turn on multi-factor authentication. This article goes into more depth.