Preventing a Critical Identity Breach

Fig.1

Fig.2

The hackers, who had compromised the vendor’s email account, responded with a link claiming to provide the missing attachment.
Fig.3

When the director clicked the link, they were taken to a convincing fake website that prompted them to enter their Microsoft credentials. Entering the information allowed the attackers to steal the username, password, and the multi-factor authentication (MFA) session token, giving them full access to the account.
Shortly afterwards, the attackers signed in using a VPN (MULLVAD_VPN) from IP address 104.193.135.105. They accessed the account through unmanaged devices and browsers inconsistent with the director’s normal login patterns, including Edge and Firefox on MacOS. Our monitoring system identified these anomalies immediately:
- Authentication from unmanaged devices outside the organisation’s control
- Use of a VPN indicating potential masking of attacker location
- Authentication attempts bypassing MFA, suspicious due to previously enforced MFA
- Multiple browsers and operating systems inconsistent with the user’s normal behaviour
The attackers created malicious inbox rules to hide their activity, such as auto-deleting emails containing keywords related to security alerts or suspicious login notifications.
Fig.4

Sign-in logs from Microsoft 365 clearly showed anomalous authentication patterns, including inconsistent browsers and geographies.
Fig.5

Key Remediation Actions
- Immediately revoked all active sessions, logging out the attacker
- Disabled the compromised account to prevent further access
- Reviewed and removed malicious inbox rules
- Rotated the compromised credentials
- Reviewed account activity to understand attackers’ intent and damage
- Recommended user security awareness training to prevent recurrence
The swift detection and intervention prevented the attackers from sending emails from the compromised account or moving laterally within the environment. The client avoided financial losses and reputational damage. This incident highlights the critical importance of real-time identity monitoring, behavioural analysis, and rapid response to defend against sophisticated phishing and credential theft campaigns.
Potential Impact & Attacker Next Steps if Undetected
A successful credential theft and account takeover can lead to attackers sending mass phishing emails from a trusted account, spreading ransomware, stealing sensitive company or customer data, or gaining access to financial systems to commit fraud. Attackers often create additional inbox rules to hide their presence, establish persistent backdoors, and use the compromised account to move laterally through the network, targeting other accounts or cloud services. Over time, this can result in severe financial loss, regulatory penalties, and significant reputational damage for the business.



