logo

Stories from the SOC: The curious case of termination notices

ID: 3faea03e-6836-5457-b953-46d3b3e3c11d

STIX ID: report--3faea03e-6836-5457-b953-46d3b3e3c11d

Feed Name: Expel Blog

Threat Score
55/100

Date Published: 2025-10-29

Date Updated: 2026-04-27

Author: Ben Nahorney; Isa Judd; Hafsah Mijinyawa

...
...

This SOC report describes a multi-stage phishing campaign at a university: attackers compromised student accounts (Student 0 and Student 1), used them to send phishing emails to about 4,800 recipients containing credential-harvesting forms, and established inbox rules to hide activity; SOC analysts pivoted on a suspicious IP to uncover the broader campaign, disabled affected accounts, reset credentials, and blocked malicious domains to contain the incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.