Beyond the Inbox: How BEC Leads to SSO Abuse
For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim's mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money or sensitive information. Today, we're seeing something different at LevelBlue. Across multiple recent investigations, we've observed attackers treating a compromised mailbox as just the first step.