One click to "Continue" is all it takes to hand an attacker your entire mailbox — no password, no malware, no alarms. In this video, Rajan Kapoor VP of Security at Material Security, builds and deploys a malicious OAuth app to prove it, walking through live email exfiltration, lateral movement into connected services, and covert message deletion that leaves no trace. He also flags where Google's own consent screens fall short. Watch to see how invisible this kind of compromise can be to the victim.

Author Bio: Rajan Kapoor is Vice President of Security at Material Security, where he leads efforts to protect sensitive data and secure modern SaaS environments for cloud-first organizations. He brings more than two decades of experience in security architecture, data protection, and enterprise infrastructure. Prior to Material Security, Rajan held security leadership roles at Dropbox, including Director of Security and Head of Data Security, where he focused on safeguarding customer data and securing large-scale cloud platforms. His work centers on building practical, scalable security programs that help organizations manage risk while enabling the business to move quickly.


Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter and LinkedIn to read more exclusive content we post.