The ToddyCat group’s new Umbrij malware is stealing corporate Gmail access by hijacking browser sessions instead of cracking passwords, bypassing standard security measures entirely. This "Shadow Token" technique allows attackers to silently read emails and redirect payments, contributing to the $8.5 billion lost globally to email fraud last year. Businesses face immediate cash losses and investigation costs averaging $75,000, with 83% of stolen funds often never recovered. To survive this threat, companies must immediately audit their OAuth app connections and block remote debugging ports before attackers turn your inbox into an open vault.