2026 Critical Cloud Identity Detection: Mail-Scoped Consent Grant Followed by In

Detects a potential Business Email Compromise (BEC) persistence chain where a user grants an OAuth application mail-read or mail-write permissions, followed by the creation of a malicious inbox rule designed to forward, move, or delete sensitive email threads. This combination enables persistent exfiltration and stealth, bypassing password resets as the OAuth token remains active.