Decision RecordActivePublished without chair review
CRT-2026-022110 Aug 2026AFTERNOON EDITIONDaily Roundtable
Identity session and approval workflow hardening
Treat phishing-kit takedown as disruption, not remediation: revoke risky Microsoft 365 and Entra sessions and refresh tokens, inspect OAuth grants, require phishing-resistant MFA for high-risk roles, shorten session persistence, and move payment, payroll, vendor-bank, HR, and help-desk approvals to out-of-band dual control rather than relying on voice, video, email, or chat alone.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Under reviewThe decision is timely because the Roundtable evidence describes two active control failures converging at once.
The identity analysis says BKA/ZIT seized more than 200 Kratos/Sneaky2FA servers, but warns that Microsoft 365/OIDC session cookies and tokens can survive beyond the phishing infrastructure.
The deepfake analysis says AI-powered BEC is already affecting payments, payroll, and evidence integrity, not merely future deepfake-detection purchasing.
The moderator synthesis on 2026-08-09 connected those lanes into one operational lesson: after the initial lure, attackers can still abuse identity sessions and approval workflows unless those paths are hardened now.
Who is affected
Under reviewMicrosoft 365 and Entra operators are affected because the packet describes AiTM session theft against Microsoft 365/OIDC authentication, where session cookies or tokens can remain useful after password rotation.
Administrators of high-risk roles are affected because the recommended controls specifically include phishing-resistant MFA, session and refresh-token revocation, OAuth grant inspection, and shorter session persistence.
Finance teams handling payments and vendor-bank changes are affected because the deepfake analysis frames AI-powered BEC as an active payments problem and says voice, video, email, or chat alone should not authorize high-risk requests.
Payroll and HR teams are affected because payroll changes and sensitive HR actions can be initiated through impersonation and need out-of-band dual control.
Help-desk teams are affected because account recovery and MFA changes can become approval-chain entry points and should not rely on a single conversational channel.
What supports this
Under reviewThe identity architect’s Kratos/Sneaky2FA analysis supports the identity-control portion: it says BKA/ZIT seized more than 200 servers, but also says AiTM kits can relay Microsoft 365/OIDC sessions and steal session cookies or tokens, so takedown does not remove session risk.
The same analysis supports revoking risky sessions and refresh tokens, inspecting OAuth grants, requiring phishing-resistant MFA for high-risk roles, and shortening session persistence.
The deepfake fraud analysis supports the approval-control portion: it says AI-powered BEC is already a payments, payroll, and evidence-integrity problem, and cites executive/vendor deepfakes, voice cloning, spoofed calls, IC3 2025 BEC losses of $3.046B, and the $25M Arup video-call fraud.
The moderator synthesis supports combining these into one operational decision: it says the initial exploit or lure matters less than whether identity, approval, and recovery paths can be hijacked afterward.
The evidence review supports the combined recommendation and separately flags the manager-targeting detail as a wording-only evidence gap, not a reason to drop the core controls.
How the Roundtable reached this
Under reviewThe identity analysis treated the Kratos/Sneaky2FA takedown as disruption, not risk removal, because AiTM kits can relay Microsoft 365/OIDC sessions and steal session cookies or tokens.
The deepfake analysis separately framed AI-powered BEC as a payments, payroll, and evidence-integrity problem, citing executive/vendor deepfakes, voice cloning, spoofed calls, IC3 2025 BEC losses of $3.046B, and the $25M Arup video-call fraud.
The moderator then joined the two lanes into one operational lesson: identity, approval, and recovery paths must resist hijacking after the initial lure.
The evidence review accepted the session, token, OAuth, MFA, persistence, and out-of-band approval controls, while limiting any specific manager-targeting claim because the underlying source detail was thin.
The arbiter selected a new operational-action record because no prior matching decision was identified.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 8 candidate signals.
- Linker (AI panel role)Linker evaluated 8 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 12 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
- Arbiter (AI panel role)Arbiter produced 8 decision envelopes.
Key disagreement
Scout (AI panel role)
Manager-targeting detail was limited in the visible evidence, and the Levi Strauss scope says consumer data was not impacted on current findings. The core decision does not depend on those claims alone.
Arbiter outcome
Arbiter outcome: new decision record. The identity-session and approval-control position is supported as a new operational action, no existing record was identified, and the remaining source-specificity gap is handled by general control-focused wording.
Candidates considered
Considered 8 candidates · opened 1 · 7 not opened (7 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe control recommendation is supported, but exposure is tenant- and workflow-specific.
The packet does not show whether a given Microsoft 365 or Entra deployment has active token replay, risky OAuth grants, mailbox rules, or weakened MFA methods. It also does not establish a specific manager-targeting report strongly enough to quote directly.
The deepfake evidence supports approval-chain hardening for payments, payroll, HR, vendor-bank, and help-desk workflows, but it does not prove that every such workflow has been targeted in the same way.
What evidence is missing
MissingThe packet does not include private Microsoft 365 or Entra tenant logs showing which accounts have stolen sessions, refresh tokens, OAuth consents, mailbox rules, or MFA method changes.
It also does not include the underlying source detail needed to quote manager-targeting as a direct, source-backed driver. The Levi Strauss scope note in the review says consumer data was not impacted on current findings, so this record should not be read as evidence of consumer-data exposure.
No private payment, payroll, HR, vendor-bank, or help-desk approval logs are included to prove that a specific organization’s workflow has already been abused.
What would change this
Under reviewThis decision would narrow if tenant review shows no high-risk Microsoft 365 or Entra accounts, no risky sessions or refresh tokens, no suspicious OAuth grants, no mailbox-rule abuse, no MFA method changes, and no sensitive approval workflows exposed to voice, video, email, or chat-only authorization.
It would strengthen if incident logs show token replay, malicious OAuth consent, mailbox-rule abuse, MFA tampering, or a payment, payroll, HR, vendor-bank, or help-desk approval attempt initiated through deepfake or impersonation.
It would also change if authoritative source detail is added that directly proves manager-targeting, because that claim is currently treated as a general risk driver rather than a quoted finding.
What to watch next
Under reviewFor the next 72 hours, review Microsoft 365 and Entra sign-ins, token replay indicators, OAuth consents, mailbox rules, MFA method changes, and sensitive approvals.
Escalate if high-risk accounts show unusual sessions, new OAuth grants, new mailbox rules, MFA changes, or approval requests tied to money movement, payroll, vendor-bank changes, HR actions, or help-desk recovery.
If no high-risk accounts or payment workflows are exposed, tune the emergency response, but keep out-of-band authorization as the baseline control for sensitive approvals.
Evidence basis
The strongest signal from this round is that four different lanes are converging on the same operational lesson: the initial exploit or lure is less important than whether the organization’s approval, identity, and recovery paths can be hij…
Summary: Metabase is the highest-confidence, tonight-action item: per the briefing, a CVSS 10.0 unauthenticated SQL injection zero-day was exploited in the wild to gain admin access, steal credentials, and exfiltrate connected data, with Fr…
Public value history
- 10 Aug 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 09 Aug 2026Methodology
How the panel reaches a Public Decision Record.