Business Email Compromise with Forwarding Rule and OAuth Abuse
- Business Impact
- An attacker gained access to a finance user's mailbox via a phishing-derived OAuth grant, created a hidden forwarding rule, and used the mailbox to intercept invoice communications and attempt fraudulent wire redirection.
- Recommendation
- Revoke the malicious OAuth grant, remove forwarding rules, reset credentials and sessions, harden conditional access, enforce phishing-resistant MFA, and add detections for suspicious OAuth grants and mailbox rule changes.