Recent Phishing Incident

Recently, one of our customers experienced a targeted phishing attack that aimed to compromise their Microsoft 365 account. Because transparency and security are core to how we operate, we want to share what happened, how we responded, and the steps taken to ensure the customer’s environment remains secure.

What Happened

On the morning of Thursday 12th March, a user at the customer’s organisation received a sophisticated phishing email claiming they needed to sign in to Microsoft 365 to view a OneNote document. The link led to a fraudulent login page designed to harvest the user’s credentials.

After the user entered their details, the attacker captured a session cookie, which allowed them to bypass normal authentication and temporarily access the user’s Microsoft 365 account.

This type of attack—known as session hijacking—is increasingly used in modern phishing campaigns because it lets attackers log in without needing the actual password.

What the Attacker Did

Once inside the mailbox, the attacker:

  • Logged in from an IP address in the United States
  • Sent phishing emails to the user’s address book and autocomplete contacts to spread the attack further
  • Created a mailbox rule that moved all new emails to Deleted Items and marked them as read to avoid detection

The affected user did not store documents or sensitive data in Microsoft 365 beyond standard email and Teams communication, which helped limit exposure.

Importantly, there is no evidence that the attacker accessed, downloaded, or exfiltrated any data.

How We Responded

As soon as we were alerted to suspicious sign‑in activity, we took swift action to contain and secure the environment. Our response included:

  • Revoking all active user sessions
  • Resetting the user’s password
  • Verifying MFA devices to ensure only legitimate authentication methods were present
  • Removing the malicious inbox rule
  • Reviewing sign‑in and activity logs to confirm what actions the attacker took
  • Monitoring the account closely after remediation

Following these actions, no further unauthorised access was detected.

Assessment of Impact

Our investigation confirmed:

  • No sensitive or special category data was accessed
  • The attacker’s activity was focused on spreading phishing messages, not data theft
  • The customer’s internal and external contacts may have received phishing emails during the incident
  • Overall, the risk of harm to individuals was assessed as low

We also supported the customer in assessing their regulatory obligations and confirming that no ICO notification was required.

What We’re Doing Going Forward

Although the incident was contained quickly, we are committed to continuous improvement. We have taken the following preventative steps:

  • Enhanced Conditional Access and sign‑in risk detection
  • Delivered additional phishing‑awareness training to the affected user
  • Reviewed mailbox rules and forwarding configurations across the tenant
  • Continued monitoring of the environment for any anomalies

A Final Note

Phishing and credential‑harvesting attacks are becoming more sophisticated, but rapid response and layered security controls make a huge difference in limiting risk and preventing escalation.

We’re proud of the swift and collaborative work carried out with our customer to contain this incident, prevent further spread, and reinforce long‑term security.

If your organisation has concerns about phishing, account compromise, or Microsoft 365 security, we’re here to help.

TAGS

CATEGORIES

Uncategorised

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top