By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Security Superlatives: 2025’s Phishiest Attacks and Boldest Offenders” (December 9, 2025)

TL;DR: 2025 phishing campaigns abused DKIM replay, OAuth consent flows, lookalike domains, and fabricated threads to make malicious email look legitimate while still bypassing SPF, DKIM, DMARC, or MFA controls, according to Abnormal AI. The lesson is that trust signals alone no longer prove intent, so identity, mailbox, and consent governance must be treated as one control surface.


At a glance

What this is: This is Abnormal AI's analysis of four phishing patterns that exploited trusted email and identity signals, showing that authentication alone did not stop malicious lures.

Why it matters: It matters because email, IAM, and consent governance are converging control surfaces, and teams that treat SPF, DKIM, DMARC, or MFA as sufficient will miss abuse that happens inside trusted flows.


Context

Authenticated email means a message can pass technical checks such as SPF, DKIM, and DMARC without proving that the sender's intent is legitimate. In these campaigns, attackers used those trust signals as cover for phishing lures, credential theft, and OAuth consent abuse, which makes the identity control problem broader than email filtering alone.

For IAM teams, the important shift is that mailbox access, OAuth consent, and post-authentication access are now part of the same risk surface. If a malicious app can gain persistent API access, or if a replayed message looks genuine enough to trigger action, then traditional trust signals no longer map cleanly to user intent or authorisation state.


Key questions

Q: What breaks when authenticated email is treated as proof that a message is safe?

A: You lose the distinction between message delivery and message legitimacy. SPF, DKIM, and DMARC can show that a message travelled through a valid path, but they cannot prove the sender's intent, the freshness of the content, or whether the embedded request is malicious. That is why authenticated phishing succeeds even when the technical checks all pass.

Q: Why do OAuth attacks bypass MFA so often?

A: OAuth attacks bypass MFA because the attacker is not asking the user to log in again after the token is issued. Once consent is granted, the bearer token can be replayed without another authentication challenge. That is why consent phishing and token theft are so effective against environments that rely only on login controls.

Q: How can security teams spot phishing kits that evade static scanners?

A: Look for behavioural anomalies rather than only bad domains or file signatures. Cloud-hosted lures, bot-blocking responses, unusual redirect chains, and mismatches between sender identity and request context are stronger indicators than a single malicious indicator. If the page is designed to look normal to scanners, the detection model must evaluate the interaction pattern.

Q: Should email security and IAM teams handle phishing as one control problem?

A: Yes. Modern phishing often crosses inbox, consent, and mailbox controls in a single flow, so separate teams can miss the full attack path. A useful operating model is to join message authentication, identity consent review, and post-authentication monitoring so that a trusted-looking email cannot independently grant durable access.


Technical breakdown

Why DKIM replay breaks message trust

DKIM proves that a message was signed by a domain key and was not altered after signing. It does not prove that the message is safe, trustworthy, or newly authored. In the campaign described by Abnormal AI, attackers reused a legitimate signed alert and shifted the lure into another field, which allowed SPF, DKIM, and DMARC to pass while the malicious action still rode inside the message. ARC can preserve authentication results across forwarding hops, so downstream systems may inherit trust that the original context no longer deserves.

Practical implication: Treat authenticated email as a transport property, not a legitimacy verdict.

How OAuth consent becomes a mailbox back door

OAuth consent is an authorisation decision, not a login event. When a user approves an unverified app, the app can receive persistent API access to the mailbox or related data without needing the password again. That access can survive password resets because the token or granted permission exists independently of the original login session. In the article's Teams invite example, the consent screen was the real control boundary, and MFA did not help because the abuse happened after authentication, inside the delegated access flow.

Practical implication: Review consent grants as privileged access, not as ordinary user activity.

Why static phishing detection misses modern lure design

Rule-based email security depends on observable indicators such as known bad domains, file hashes, or reused templates. Modern phishing kits increasingly hide behind fresh domains, compromised business accounts, cloud hosting, and bot-evasion responses such as HTTP 403 blocks. The result is a campaign that looks normal enough for a scanner but abnormal enough in behaviour to reveal intent. The problem is not just evasion, but the fact that attackers now compose legitimacy out of brand cues, calendar norms, and procedural language that the recipient expects to see.

Practical implication: Augment static filters with behavioural detection that scores sender intent and conversation context.


Threat narrative

Attacker objective: The attackers wanted legitimate-seeming access to mailboxes and identity workflows so they could steal credentials, persist in accounts, and continue phishing from trusted channels.

  1. Entry occurred through trusted delivery paths, including replayed DKIM-signed alerts and calendar invites that passed SPF, DKIM, and DMARC.
  2. Credential or consent acquisition followed when victims either entered credentials into fake login pages or approved malicious OAuth apps.
  3. Escalation came through persistent mailbox or API access that survived password resets and enabled follow-on phishing or data collection.
  4. Impact was mailbox compromise, credential theft, and durable access to email data and user identity flows.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Authenticated email is not an identity guarantee: SPF, DKIM, and DMARC validate parts of the delivery path, but they do not validate the sender's intent or the legitimacy of the embedded request. Abnormal AI's examples show that attackers now use the trust boundary itself as the lure, not just the message content. The practical conclusion is that email authentication must be treated as one input to risk scoring, not as proof that the communication deserves action.

Consent governance is the new mailbox perimeter: OAuth consent turns a user interaction into delegated authority that can outlive the login session. That means mailbox security is no longer just about passwords, MFA, or inbox hygiene; it is also about which apps can obtain durable API access and who can review those grants. For IAM and IGA teams, the control surface has moved from sign-in to authorisation artefacts.

Static phishing controls fail when legitimacy is assembled, not forged: The campaigns described here did not rely on obvious malware or crude spoofing. They stitched together brand cues, meeting norms, vendor language, and trusted infrastructure so that the message looked procedurally correct. That exposes a governance blind spot: defenders still expect phishing to look abnormal, while attackers increasingly make it look administratively normal.

Email, IAM, and collaboration controls now share one abuse path: The same lure can traverse inbox, calendar, OAuth, and mailbox layers before a human realises anything is wrong. That makes siloed ownership a liability because the attack does not respect product boundaries. Security teams should treat message delivery, identity consent, and post-authentication access as one connected control problem.

Identity trust signals need a new operating model: The naming pattern here is useful: authenticated phishing. It describes a class of attacks where the infrastructure signals are clean but the behavioural and authorisation signals are malicious. That framing should push programmes away from signature confidence and toward continuous verification of sender behaviour, consent intent, and delegated access scope.

From our research library:

What this signals

Authenticated phishing is now a governance category, not just a message type: Programmes that rely on email authentication as the last word on legitimacy are underreading the risk. The operational question is no longer whether the message passed SPF or DKIM, but whether the request, sender history, and downstream authorisation state align.

Consent artefacts need lifecycle control: OAuth grants, mailbox permissions, and app approvals behave like standing access until somebody revokes them. That makes consent review, app inventory, and offboarding part of the same identity lifecycle problem that IAM teams already manage for privileged access.

Behavioral intent should outrank technical cleanliness: A clean signature can coexist with a malicious objective. Security programmes should therefore elevate sender behaviour, conversation context, and unusual access patterns above reputation-only filtering when deciding what is safe to trust.


For practitioners

  • Tighten OAuth consent review Inventory all enterprise OAuth grants, flag unverified apps, and require formal review for apps that request mailbox or message-read permissions.
  • Correlate email and identity signals Correlate authenticated email events with sender reputation, conversation history, and consent events so a clean DKIM result does not override suspicious behaviour.
  • Hunt for persistent mailbox access Look for API access that remains after password resets, especially where a recent consent event was followed by unusual mailbox reads or forwarding rules.
  • Test scanner blind spots Exercise phishing detection against bot-blocking pages, cloud-hosted lures, and multi-hop redirect chains to confirm that static indicators are not your only signal.
  • Separate authentication from authorisation Treat SPF, DKIM, DMARC, and MFA as necessary controls, but route high-risk requests through separate authorisation checks before users can approve payment, vendor, or access changes.

Key takeaways

  • Authenticated phishing succeeds because trust signals such as SPF, DKIM, DMARC, and MFA can be technically valid while the request itself is malicious.
  • The article's examples show two especially important failure modes: replayed signed email and OAuth consent that leaves persistent mailbox access behind.
  • Teams reduce exposure by treating email, consent, and post-authentication access as one governance surface rather than separate defensive problems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationAuthenticated phishing shows that valid delivery signals can still hide malicious identity flows.
NHI-10 — Human Use of NHIOAuth consent and delegated mailbox access turn human actions into machine-granted authority.
Recommendation — Audit identity flows where authentication signals are clean but the sender's intent or grant scope is not. Restrict human approval paths that create durable machine access without separate governance review.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPersistent access and credential abuse depend on weak management of authenticators and grants.
Recommendation — Revoke or rotate authenticators and delegated access when consented access is no longer required.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsOAuth consent and mailbox access are entitlements that need ongoing review and control.
Recommendation — Review and constrain entitlements that allow mail and API access after initial sign-in.
OWASP API Security Top 10API2 — Broken AuthenticationOAuth abuse and persistent mailbox access illustrate abuse of authentication and token-based trust.
Recommendation — Validate token issuance, consent scope, and revocation paths for mailbox-connected APIs.

Key terms

  • OAuth Phishing: OAuth phishing is a social engineering technique that tricks a user or administrator into granting a malicious application access through an OAuth consent flow. The attacker does not always need a password. Instead, they exploit delegated authorization to obtain tokens, permissions, or persistent access to data and connected services.
  • OAuth Consent: The approval that allows an application to access resources on behalf of a user or tenant. In practice, consent can create durable access paths that outlive the original interaction if permissions are broad, unmanaged, or never reviewed. For security teams, it is both an access decision and a lifecycle event.
  • DKIM replay: DKIM replay is the reuse of a legitimately signed email so it continues to appear authenticated after the attacker modifies the lure elsewhere in the delivery chain. The signature may still validate, but the message can be repurposed to support phishing or fraud.
  • Delegated Mailbox Access: Delegated mailbox access is permission that allows one account or user to read, send, or manage another mailbox. It is useful for operations, but it increases blast radius if the delegate account is abused or the permission is never reviewed.

Deepen your knowledge

NHI governance, identity lifecycle, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or NHI governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org