The attack that was simulated in my case utilized convincing social engineering, spear phishing, domain spoofing, and malicious OAuth apps meant to look like an internal resource/service to gain access to sensitive material.
It was very sophisticated and I’m glad I fell for it during a simulation rather than in a “real life” situation. It was a learning experience and a situation I’m way more paranoid about now. I could easily see admins and developers anywhere falling for it if they were specifically targeted.