A finance or executive mailbox is compromised
Through phishing or reused credentials, the attacker gains access to a mailbox belonging to finance staff or an executive whose instructions carry weight in the payment process.
Gain access to a mailbox involved in, or able to authorise, payments.
- Phishing-resistant MFA on all mailboxes
- Conditional Access restricting risky sign-ins
- User reporting and fast triage of phishing lures
- Sign-ins from unusual locations or impossible travel
- Risky sign-in alerts from identity protection
- Mail access from unfamiliar clients or IPs
- Social-engineering assessment of finance and executive staff
- Test MFA strength and Conditional Access coverage
- Review sign-in monitoring and response
The attacker can now read sensitive payment correspondence as a trusted insider.