Security is not a feature. It’s a priority — and one we take seriously every day. This post is a straightforward account of how we think about phishing abuse on our platform and what we’re building to reduce the risk that our infrastructure is used as a vector for harm. What happened We identified a pattern of abuse in which bad actors were using our test sandboxes to trick users into granting OAuth access to accounts they didn’t intend to share. When we had sufficient understanding of the scope of the issue, we moved quickly.