Join our Newsletter — 33% off our NHI Course

OAuth token theft and BEC: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: A phishing-as-a-service platform is using legitimate Microsoft sign-in flows to steal OAuth tokens instead of passwords, then turning that access into persistent business email compromise, according to Abnormal AI. The core problem is that traditional credential-harvesting controls assume a fake login page or stolen password, while token theft preserves legitimate authentication context and defeats those assumptions.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Inside EvilTokens: The PhaaS Platform Stealing Tokens, Not Passwords”.

Key questions

Q: What breaks when OAuth tokens are stolen through a legitimate login flow?

A: Password-based phishing controls lose much of their value because the victim authenticates on real infrastructure and the attacker captures the token instead of a password.

Q: Why do compromised email accounts still create business email compromise risk?

A: Because once an attacker controls a valid mailbox, the messages often look legitimate to users and to some security tools.

Practitioner guidance

  • Harden OAuth consent governance Restrict app consent, review granted scopes, and investigate any token grant that creates mailbox or directory access beyond the expected user workflow.
  • Monitor for token abuse after valid logins Build detections around impossible behaviour for a newly issued token, including unusual mailbox rules, atypical send patterns, and first-time use from abnormal locations.
  • Shorten the value of captured tokens Reduce the lifetime and usefulness of bearer credentials where policy allows, and ensure revocation events actually invalidate active sessions and connected apps.

Bottom line: OAuth token theft can defeat password-centric phishing defences because the victim completes a real sign-in while the attacker captures the token that follows.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

OAuth token theft is now a primary identity compromise pattern, not a niche variant of phishing. Traditional credential-harvesting assumptions are built around fake pages and stolen passwords, but this attack path keeps the sign-in experience legitimate while moving the theft point to the token itself. That shifts the governance problem from password protection to post-authentication control of bearer credentials. Practitioners should treat token theft as a mainstream identity risk, not an email-only anomaly.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: Should organisations prioritise token revocation or password resets after suspected compromise?

A: Token revocation usually comes first when the incident involves OAuth, refresh tokens, API keys, or other delegated access. Password resets help only if the attacker depended on interactive login. When the compromise path includes connected apps, the priority is to cut off every issued credential and consented integration before restoring user access.

👉 Read our full editorial: EvilTokens shows OAuth token theft is bypassing password-based defenses


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.