TL;DR: 2025 phishing campaigns abused DKIM replay, OAuth consent flows, lookalike domains, and fabricated threads to make malicious email look legitimate while still bypassing SPF, DKIM, DMARC, or MFA controls, according to Abnormal AI. The lesson is that trust signals alone no longer prove intent, so identity, mailbox, and consent governance must be treated as one control surface.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Security Superlatives: 2025’s Phishiest Attacks and Boldest Offenders”.
Key questions
Q: What breaks when authenticated email is treated as proof that a message is safe?
A: You lose the distinction between message delivery and message legitimacy.
Q: Why do OAuth attacks bypass MFA so often?
A: OAuth attacks bypass MFA because the attacker is not asking the user to log in again after the token is issued.
Q: How can security teams spot phishing kits that evade static scanners?
A: Look for behavioural anomalies rather than only bad domains or file signatures.
Practitioner guidance
- Tighten OAuth consent review Inventory all enterprise OAuth grants, flag unverified apps, and require formal review for apps that request mailbox or message-read permissions.
- Correlate email and identity signals Correlate authenticated email events with sender reputation, conversation history, and consent events so a clean DKIM result does not override suspicious behaviour.
- Hunt for persistent mailbox access Look for API access that remains after password resets, especially where a recent consent event was followed by unusual mailbox reads or forwarding rules.
Bottom line: Authenticated phishing succeeds because trust signals such as SPF, DKIM, DMARC, and MFA can be technically valid while the request itself is malicious.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authenticated email is not an identity guarantee: SPF, DKIM, and DMARC validate parts of the delivery path, but they do not validate the sender's intent or the legitimacy of the embedded request. Abnormal AI's examples show that attackers now use the trust boundary itself as the lure, not just the message content. The practical conclusion is that email authentication must be treated as one input to risk scoring, not as proof that the communication deserves action.
A few things that frame the scale:
- Security researchers tracked consent phishing campaigns affecting 900 tenants and 3,000 user accounts in 2025.
A question worth separating out:
Q: Should email security and IAM teams handle phishing as one control problem?
A: Yes. Modern phishing often crosses inbox, consent, and mailbox controls in a single flow, so separate teams can miss the full attack path. A useful operating model is to join message authentication, identity consent review, and post-authentication monitoring so that a trusted-looking email cannot independently grant durable access.
👉 Read our full editorial: Authenticated phishing lures expose the limits of email trust signals