Stories from the SOC: The curious case of termination notices
ID: 3faea03e-6836-5457-b953-46d3b3e3c11d
STIX ID: report--3faea03e-6836-5457-b953-46d3b3e3c11d
Feed Name: Expel Blog
Date Published: 2025-10-29
Date Updated: 2026-04-27
Author: Ben Nahorney; Isa Judd; Hafsah Mijinyawa
This SOC report describes a multi-stage phishing campaign at a university: attackers compromised student accounts (Student 0 and Student 1), used them to send phishing emails to about 4,800 recipients containing credential-harvesting forms, and established inbox rules to hide activity; SOC analysts pivoted on a suspicious IP to uncover the broader campaign, disabled affected accounts, reset credentials, and blocked malicious domains to contain the incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
