By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Phishing 2.0: Duo Passcodes Under Siege in Higher Education” (June 26, 2026)

TL;DR: A single phishing email can now compromise entire education networks by abusing trusted platforms such as Google Forms and Microsoft SharePoint, while AI-written lures, trusted-sender abuse, and OTP relay accelerate lateral phishing across cloud environments, according to Abnormal AI. Trusted communication channels have become an identity problem, not just an email problem.


At a glance

What this is: This webinar examines how phishing campaigns in education abuse trusted collaboration tools and identity workflows to turn one message into account compromise and lateral phishing.

Why it matters: It matters because education security teams have to govern trust across email, collaboration platforms and identity recovery paths, not just block suspicious messages.


Context

Phishing in education is no longer confined to obvious malicious email. The governance gap is that trusted tools such as collaboration forms, document-sharing platforms and one-time passcode workflows can be turned into delivery and compromise paths when defenders treat each channel in isolation.

In K-12 and higher education, that creates an IAM problem as much as an email security problem. A single credential theft event can be used to move laterally through cloud services, abuse trusted sender relationships and amplify access beyond the initial mailbox.

Abnormal AI frames the issue as a change in attacker method, but the underlying challenge is programme design: institutions need controls that follow identity and trust across channels. For education environments, that is now a normal operating condition, not an edge case.


Key questions

Q: What fails when phishing uses trusted collaboration tools instead of obvious malicious links?

A: The failure is a trust model that treats collaboration tools as safe by default. When Google Forms, SharePoint or similar services are used as lures, users and controls may see a legitimate platform while the request itself is hostile. Security teams need to govern trust in the channel, not only in the sender reputation.

Q: Why does OTP relay increase account takeover risk in education environments?

A: OTP relay works because the attacker uses a valid code before the authentication moment expires. In education environments, that means a single successful lure can finish the login flow even when the user believes they are protecting the account. The risk rises when verification depends on a short-lived code without stronger channel or device binding.

Q: What are the signs that phishing is spreading through collaboration tools instead of email?

A: A common sign is an unusual burst of urgent messages, often tied to fake support requests, credential prompts, or malicious links sent through Teams, Slack, Zoom, or similar tools. Another signal is a mismatch between the channel and the request, especially when users are being pushed to act immediately. Security teams should also watch for repeated clicks from multiple devices or users.

Q: How should education security teams reduce the blast radius after a single phishing account compromise?

A: They should constrain the trust extensions that let one account become a relay for more compromise. That means reviewing delegated access, mailbox rules, shared collaboration spaces and recovery workflows together, because attackers exploit the connections between them rather than one control in isolation.


Background and context

How trusted collaboration tools become phishing infrastructure

Attackers increasingly use legitimate collaboration services such as Google Forms and Microsoft SharePoint as part of the phishing path rather than as the final target. Those platforms inherit trust from the organisation, which helps the lure bypass basic reputation checks and user suspicion. In practice, the malicious content is not hosted on an obviously hostile domain, so the attack blends into normal work patterns. That changes the defensive problem from message filtering alone to validating the trust relationship behind the link, form or file request.

Practical implication: inspect and govern trusted SaaS channels as potential delivery infrastructure, not just as productivity tools.

Why OTP relay and trusted-sender abuse defeat email-only controls

OTP relay works by capturing a one-time passcode in real time and using it before it expires, while trusted-sender abuse exploits internal or familiar communication paths to reduce scrutiny. Both tactics compress the response window and make old assumptions about message origin unreliable. Once the attacker can reuse a trusted channel, the real control question becomes whether the identity assurance step is bound to the right session, device or transaction. Email security products may see a legitimate sender pattern while the identity layer is already being bypassed.

Practical implication: bind authentication, session and sender verification controls more tightly so that a trusted channel cannot carry an untrusted request.

How lateral phishing turns one compromised account into cloud spread

Lateral phishing begins after initial credential theft, when the attacker uses the compromised account to send believable messages to internal contacts and peers. In cloud-heavy education environments, that can propagate through Microsoft 365, Google Workspace and related services quickly because recipients trust messages from within their own collaboration graph. The technical weakness is not just the first compromise but the absence of containment around account behavior, mailbox rules and outbound trust. Once an account is allowed to function as a relay, the blast radius expands well beyond the original inbox.

Practical implication: monitor account-to-account phishing behaviour and constrain post-compromise propagation paths inside collaboration platforms.


NHI Mgmt Group analysis

Trusted-channel phishing is now an identity governance problem, not a mail-filter problem. When attackers weaponise Google Forms, Microsoft SharePoint and trusted-sender paths, the control boundary moves from message inspection to trust lifecycle governance. Education institutions that still treat collaboration tools as separate from identity policy are protecting the wrong layer. The practitioner implication is to govern trust paths end to end, not inbox by inbox.

OTP relay collapses the assumption that verification happens before access is granted. One-time passcodes only work when the verification event and the use of that event are tightly coupled. In real-time relay attacks, that coupling breaks, and the identity proof is consumed by the attacker before the defender can react. The implication is that time-bound authentication without channel binding is fragile in education phishing scenarios.

Lateral phishing exposes the identity blast radius hidden inside cloud collaboration graphs. A compromised account is not just a mailbox problem if it can be used to seed further trust-based compromise across Microsoft 365 and Google Workspace. The risk is amplified in K-12 and higher education because internal relationships are dense and message trust is high. Practitioners need to think in terms of propagation potential, not just initial compromise.

Education is a high-trust environment, which makes social proof an attack surface. Staff and students are conditioned to trust familiar systems, shared documents and institution-branded flows. That makes trusted-sender abuse and familiar-tool abuse more effective than generic spam. The implication for security leaders is that user trust assumptions have to be actively measured and constrained, not presumed.

Identity trust chaining: a single verified interaction can cascade into multiple trusted follow-on actions when collaboration, authentication and message trust are not governed together. That is the core pattern this article surfaces across education phishing. It is the reason email security alone no longer defines the defense boundary. Practitioners should treat chained trust as the governing concept for this class of attack.

From our research library:

  • Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.

What this signals

Identity trust chaining: education phishing is increasingly about chaining one trusted action into the next, which means the control boundary has to extend from mail intake to authentication and collaboration permissions. If institutions only tune spam filters, they miss the propagation mechanics that make one compromised account useful.

Security teams should expect collaboration suites to function as part of the phishing delivery layer, especially where internal sender trust is high. The operational question is not whether a message looks familiar, but whether that familiarity can be weaponised into account takeover or lateral spread.


For practitioners

  • Map trusted collaboration channels to identity risk Catalogue which forms, file-sharing spaces, and messaging paths can initiate or amplify authentication events, and treat them as part of the phishing attack surface.
  • Harden OTP and recovery workflows Reduce the value of real-time code relay by tightening session binding, device checks, and help-desk recovery paths that attackers can abuse after the lure lands.
  • Detect lateral phishing behaviour inside cloud suites Monitor for unusual internal sends, rapid message forwarding, and account-to-account trust abuse across Microsoft 365 and Google Workspace.
  • Limit the blast radius of a single compromised account Apply policy and monitoring to mailbox rules, delegated access, shared drives, and other trust extensions that let one account seed further compromise.

Key takeaways

  • The article shows that trusted tools in education can be turned into phishing infrastructure, so the risk is now distributed across email, collaboration and identity flows.
  • A single account compromise can spread laterally through cloud suites, which makes the blast radius a governance problem as much as a detection problem.
  • The practical response is to govern trust paths, authentication flows and collaboration permissions together instead of treating them as separate controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHITrusted tools and OTP relay exploit human trust in identity workflows, a core NHI-adjacent misuse pattern.
Recommendation — Review human-assisted trust paths and restrict how users can activate identity flows through collaboration tools.
NIST SP 800-63SP 800-63B — AuthenticationOTP relay undermines authentication assurance and session integrity in the identity flow.
Recommendation — Strengthen authentication beyond OTPs by binding verification to the device, session, or transaction.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsLateral phishing depends on overly broad trust and access paths across cloud collaboration suites.
Recommendation — Limit entitlements and trust extensions so one compromised account cannot propagate access across services.
CIS Controls v8CIS-5 — Account ManagementAccount takeover and post-compromise spread hinge on how accounts are governed and monitored.
Recommendation — Harden account management, review delegated access, and monitor for abnormal outbound trust behavior.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article describes credential theft followed by spreading attacks across cloud identities.
Recommendation — Map phishing detections to credential access and lateral movement to spot the post-compromise spread pattern.

Key terms

  • Trusted-sender abuse: A phishing technique that exploits the legitimacy of a known sender, shared mailbox, or familiar collaboration context to increase user trust. In practice, it turns existing identity relationships into delivery infrastructure for credential theft, session hijacking, and follow-on compromise.
  • OTP relay: An attack pattern where a one-time passcode is captured and reused fast enough to complete authentication before it expires. The user still appears to have authenticated normally, but the resulting session belongs to the attacker, which makes detection harder and containment more urgent.
  • Lateral phishing: Lateral phishing is the use of a compromised internal account to send malicious messages to other users or partners. Because the sender is trusted, detection becomes harder and the attack can spread through familiar communication channels before controls react.
  • Identity Trust Chain: The sequence of trust decisions that connects a message, user, application, model, tool, and credential into one working path. When any link is weak, an attacker can move from content manipulation to access abuse without needing a separate breach at each layer.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org