Business Email Compromise via Azure Administrative Privileges
ID: 1260f85a-dc29-5afe-843e-17f16969e6d4
STIX ID: report--1260f85a-dc29-5afe-843e-17f16969e6d4
Feed Name: Huntress Blog
Threat Score
Huntress discovered and stopped a large-scale Business Email Compromise in which an Azure AD global administrator account was compromised (login from Lagos, Nigeria). The attacker created secondary admin accounts, assigned licenses, and deployed mailbox rules across many user accounts to quietly view and forward emails, repeatedly regaining access until defenders reset credentials, enforced MFA, and disabled the compromised accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
