Add Think Technology as a trusted source Preventing a Critical Identity Breach | Think Technology

Preventing a Critical Identity Breach

Graphic about phishing trends in 2025
One of our clients engaged us for comprehensive managed identity threat detection and response services. This case study details how a proactive approach prevented a severe compromise of their environment. The attack started when a director at the client’s business received an email appearing to come from a trusted vendor, requesting information and instructing them to check an attachment. However, no attachment was included.

Fig.1

The director replied to the vendor’s email, noting the missing attachment.

Fig.2

The hackers, who had compromised the vendor’s email account, responded with a link claiming to provide the missing attachment.

Fig.3

When the director clicked the link, they were taken to a convincing fake website that prompted them to enter their Microsoft credentials. Entering the information allowed the attackers to steal the username, password, and the multi-factor authentication (MFA) session token, giving them full access to the account.

Shortly afterwards, the attackers signed in using a VPN (MULLVAD_VPN) from IP address 104.193.135.105. They accessed the account through unmanaged devices and browsers inconsistent with the director’s normal login patterns, including Edge and Firefox on MacOS. Our monitoring system identified these anomalies immediately:

  • Authentication from unmanaged devices outside the organisation’s control
  • Use of a VPN indicating potential masking of attacker location
  • Authentication attempts bypassing MFA, suspicious due to previously enforced MFA
  • Multiple browsers and operating systems inconsistent with the user’s normal behaviour

The attackers created malicious inbox rules to hide their activity, such as auto-deleting emails containing keywords related to security alerts or suspicious login notifications.

Fig.4

Sign-in logs from Microsoft 365 clearly showed anomalous authentication patterns, including inconsistent browsers and geographies.

Fig.5

Key Remediation Actions

  • Immediately revoked all active sessions, logging out the attacker
  • Disabled the compromised account to prevent further access
  • Reviewed and removed malicious inbox rules
  • Rotated the compromised credentials
  • Reviewed account activity to understand attackers’ intent and damage
  • Recommended user security awareness training to prevent recurrence

The swift detection and intervention prevented the attackers from sending emails from the compromised account or moving laterally within the environment. The client avoided financial losses and reputational damage. This incident highlights the critical importance of real-time identity monitoring, behavioural analysis, and rapid response to defend against sophisticated phishing and credential theft campaigns.

Potential Impact & Attacker Next Steps if Undetected

A successful credential theft and account takeover can lead to attackers sending mass phishing emails from a trusted account, spreading ransomware, stealing sensitive company or customer data, or gaining access to financial systems to commit fraud. Attackers often create additional inbox rules to hide their presence, establish persistent backdoors, and use the compromised account to move laterally through the network, targeting other accounts or cloud services. Over time, this can result in severe financial loss, regulatory penalties, and significant reputational damage for the business.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.