- Objective
- Exfiltrate a sample of customer records from a multi-tenant SaaS platform
- Path
- No perimeter exploit was needed. A convincing “new shared inbox policy” lure sent to 40 finance staff yielded two MFA-approved AitM sessions. One account had standing consent to a third-party reporting app with Graph API scope over mailbox data — and the tenant permitted users to approve OAuth grants. Data was staged into a sanctioned-looking SharePoint folder and exfiltrated through an approved sync client.
- Detected
- The OAuth consent was logged but unmonitored; egress volume from the sync client blended into baseline
After: Tenant-wide OAuth consent restrictions, high-volume egress alerting, and a helpdesk script for verifying “policy” emails.