logo

From click to containment: How RumbergerKirk stopped a business email compromise in minutes with ThreatLocker

ID: d31f741a-abea-55fd-af05-27113b8d48ed

STIX ID: report--d31f741a-abea-55fd-af05-27113b8d48ed

Feed Name: ThreatLocker Blog

Threat Score
35/100

Date Published: 2025-09-17

Date Updated: 2026-05-01

...
...

This case study describes a business email compromise where a legitimate contact's message contained a credential-harvesting link sent to multiple employees at a law firm; one user clicked the link. The firm's CIO used ThreatLocker Unified Audit to identify the click, deployed Network Control to block the malicious domains organization-wide, and verified via logs that the threat was contained without further compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.