A payroll deposit that never arrived.
An emergency services agency lost a payroll deposit. The employee had never touched their direct deposit settings, and had never had the email conversation that appeared to authorize the change.
What it actually was: a spearphishing campaign impersonating a document delivery service, using an HTML attachment that spawned a convincing cloud sign-in and multi-factor prompt, harvested the credentials and the session token, and shipped them to a command and control server. Tradecraft consistent with a known state-linked actor. From there the attacker reset the HR system password, hid the confirmation emails in a rule-created folder, and rerouted the deposit.
By the time the work was done, five additional compromised accounts had been found, an enterprise application was discovered holding a privileged cloud administrator role, legacy authentication protocols were identified as the path around multi-factor authentication, and one workstation had a modified certificate revocation list and had to be reimaged. Sign-in log retention was seven days, which is why the true initial access date could only be bounded rather than pinned. That gap is now closed.
Financial loss stayed under five thousand dollars. Internal systems were down about a day. Emergency response capability was never affected. The agency came out of it with endpoint detection and response in place, extended log retention, conditional access, and a written record that satisfied its board and the investigating agencies.
That last part matters more than it sounds. Most organizations survive the incident and then have nothing defensible to show for it.
Talk through the incident ↗