Loading...
An organization in a regulated industry with statutory reporting obligations engaged us following an account compromise that began with a targeted phishing campaign. The organization had multi-factor authentication deployed. The attacker obtained access anyway.
That is the part worth sitting with. The control was present, correctly configured, and did not prevent the compromise — a pattern now common enough that “we have MFA” is no longer an answer to “could this happen to us”. Once inside, the attacker used the organization’s own trusted internal channels to reach further staff, which is why the activity did not look like an attack to the people receiving it.
Our work established the scope: which account was taken over, how the access was used, which internal recipients were reached, and where the exposure extended beyond the initial account. One finding concerned an endpoint outside the organization’s managed estate — a reminder that the boundary of a control is the boundary of its enforcement.
We separated what was proven from what was inferred, and identified where evidence was unavailable rather than presenting the account as more complete than it was.
Remediation went beyond ejecting the attacker. The engagement produced a prioritized set of control changes addressing both the initial access and the conditions that let it spread — distinguishing what was already audit-ready from what needed strengthening, so the organization could show an assessor a considered response rather than a scramble.
Challenge: An account was taken over despite multi-factor authentication being deployed and correctly configured. Finding: The attacker propagated through the organization’s own trusted internal channels, and exposure extended to an endpoint outside the managed estate. Outcome: Scope established from evidence, and a prioritized set of control changes an assessor can be shown.