Clarifying a potential email compromise

Shane King 71 Reputation points
2023-11-13T02:41:40.6666667+00:00

Scenario
As an M365 admin, I was called by a user who had hundreds of emails sent from their account that they did not send. When remoting into the user's device, I observed emails appearing in their draft folder in Outlook, then being sent without being recorded in the sent items folder, but do appear in the Outgoing email message trace report. Although we initially suspected a device infection, no malware was detected. Subsequently, we discovered that the user's domain was blacklisted due to an AWS IP address.

Questions

  • Is this indicative of a compromised email account?
  • Could this be a file-less attack?
  • How does the Amazon host relate to this incident?
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
{count} votes

1 answer

Sort by: Most helpful
  1. Barry Evanz 235 Reputation points
    2024-03-01T20:09:42.2733333+00:00

    The situation sounds like a compromised email account, likely without malware, suggesting a file-less or credential-based attack. The AWS IP link and domain blacklisting hint at the attacker's method, possibly leveraging cloud resources for spamming or phishing. Immediate actions include resetting passwords, enabling multi-factor authentication for added security, and scrutinizing account activities, especially for those with shared and delegated access. Such steps are crucial to regain control and secure the account against further unauthorized access. For future resilience, consider integrating a robust backup solution like Nakivo. It ensures critical data, including emails, is backed up and recoverable, safeguarding against data loss from such compromises. In short, secure the account, investigate the breach, and fortify your defenses with backup solution for example Nakivo for comprehensive data protection and quick recovery in case of future incidents.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.