Modern Business Email Compromise (BEC) attacks have evolved far beyond simple phishing into multi-stage identity abuse campaigns. Attackers exploit Google Workspace by abusing OAuth flows, session tokens, and native platform features to gain initial access, then use compromised Gmail accounts as a lateral movement engine to pivot into other SaaS platforms. Key attacker techniques include suppressing security alerts via inbox filters, establishing persistent forwarding rules and OAuth tokens that survive password resets, and leveraging trusted identities to send phishing emails internally and externally. Traditional email-focused detection fails against these campaigns because attackers use legitimate authentication flows, avoid malware, and blend into normal admin activity. Effective defense now requires Identity Threat Detection and Response (ITDR) — monitoring authentication behavior, token lifecycles, OAuth consent anomalies, and cross-platform SaaS access patterns rather than email content alone.