This talk delves into the post-compromise tactics employed by threat actors following Business Email Compromise (BEC) incidents, drawing from our experience as a Managed Security Service Provider (MSSP). We will discuss how some legitimate OAuth applications are used in post compromise for persistence and data exfiltration.