Incident
Our client reported unauthorized emails originating from their corporate Office 365 account. The messages impersonated legitimate invoicing and instructed customers to transfer funds to an attacker-controlled account.
Immediate Actions
Containment Note
We coordinated with the client to contact recipients who received the fraudulent requests and advised them to halt any pending transfers and verify payment instructions via phone or secure channel.
Response & Remediation
Outcome
Compromise was contained, no further fraudulent transfers occurred after containment steps, and affected customers were notified. The client received an updated incident playbook and technical remediation report.
Key Takeaway
Rapid containment (credential reset + revoke tokens + remove mailbox rules) combined with proactive customer communication is essential to preventing BEC financial losses.
Contact us to request the full technical report (NDA required)