Wondering if anyone else has seen this behavior.
We received an alert from MS Defender for Cloud that a suspicious IP had downloaded from a storage blob using a SAS token. It turned out that someone was misusing the SAS token feature and had sent the URL via email.
Since then, we've determined that every URL sent via email (O365) is being downloaded immediately by... someone. We brought in someone for IR but they haven't seen anything similar and we can't find a cause. We even set up two secops mailboxes (which are supposed to bypass all MS security) and sending an email between them still triggers the downloads.
The source IPs so far have all been in the US, and Spur tags most with "Oculus Proxy" and most ASNs are "Constant" or "HostRoyale". User agents match Chrome 125 or 131.
The only thing I've found online is complaints on Reddit about this causing a 100% click rate in KnowBe4. No real resolution there though.
We're thinking it's something automated/enterprise, but I want to be sure. Has anyone seen anything similar? TIA.