One MSP, Three Microsoft 365 Compromises, 72 Hours
ID: 3f654740-70f8-50cd-a676-11945b6816de
STIX ID: report--3f654740-70f8-50cd-a676-11945b6816de
Feed Name: Huntress Blog
Threat Score
Huntress reports three Microsoft 365 business email compromise incidents across an MSP’s clients (law firm, building contractor, and retail store) within 72 hours where adversaries manipulated inbox rules to redirect or hide emails and, in one case, abused administrative permissions via proxy logins to access other mailboxes; the incidents were detected by anomalous logins, user agents, and geolocated IPs, and Huntress responded by locking accounts and notifying partners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
