logo

Business Email Compromise via Azure Administrative Privileges

ID: 1260f85a-dc29-5afe-843e-17f16969e6d4

STIX ID: report--1260f85a-dc29-5afe-843e-17f16969e6d4

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress discovered and stopped a large-scale Business Email Compromise in which an Azure AD global administrator account was compromised (login from Lagos, Nigeria). The attacker created secondary admin accounts, assigned licenses, and deployed mailbox rules across many user accounts to quietly view and forward emails, repeatedly regaining access until defenders reset credentials, enforced MFA, and disabled the compromised accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.