Case Study: Stopping a Business Email Compromise

Illustration representing a Microsoft 365 email account security incident and forensic investigation during a business email compromise

The Situation

In July 2026, a staff member’s Microsoft 365 account at a Southern Oregon nonprofit was used to send a phishing campaign to hundreds of external contacts — partner organizations, vendors, and government agencies the nonprofit had worked with for years. The client noticed something was wrong almost immediately: they began receiving reports that the “spam” appeared to be coming from their own team member’s real email address.

They called Farmhouse Networking right away.

What looked at first like a single bad email turned out to be something more serious — and more instructive. The account had multi-factor authentication enabled the entire time. The attacker never broke it.

What Our Investigation Found

Rather than stopping at the surface-level fix — reset the password, re-enroll MFA, move on — our team went directly into the Microsoft 365 audit logs to understand exactly what had happened, when, and how.

The forensic trail showed a technique known as session hijacking, or adversary-in-the-middle phishing. The staff member had unknowingly entered her credentials on a fraudulent login page that relayed everything to the real Microsoft sign-in service in real time. When she completed her MFA step normally, the fraudulent page captured the session token generated afterward — the digital “you’re already logged in” credential a browser holds after a successful sign-in.

Days later, an attacker used that captured session to access the account directly. No password guess. No MFA prompt. To Microsoft’s systems, it looked like the employee logging in as usual.

From inside the account, the attacker read messages, quietly created a mail rule designed to auto-delete replies and hide the evidence, and then launched a coordinated phishing campaign — file-sharing invitations and direct emails — sent to the nonprofit’s real contact list, under the real employee’s name.

Our Response

Once we identified what had happened, our team moved through a structured containment and investigation process:

  1. Immediate account containment. We invalidated all active session tokens, reset the account password, and disabled the account — in that order, which matters. Resetting a password alone does not stop an attacker who is already holding a valid session; the session itself has to be revoked.
  2. Full forensic log review. We pulled and analyzed months of Microsoft 365 unified audit logs, sign-in records, and mailbox activity to reconstruct exactly when access occurred, what was read, what was sent, and what the attacker touched — rather than relying on assumptions about scope.
  3. Root cause identification. We traced the mechanism back to the session-hijacking technique, confirming that MFA itself had never been compromised or altered — it had simply been bypassed at a different point in the process.
  4. Closing residual exposure. Beyond disabling the account, we identified and shut down the file-sharing invitations and temporary access the attacker had created, which — if left alone — would have remained active even after the account itself was locked down.
  5. External notification support. As a courtesy, we helped the client draft a clear, professional notification email to send to everyone who had received the phishing message from their account, so partner organizations could take their own precautions and the client’s relationships stayed protected.

The Outcome

Because containment happened quickly and the investigation was thorough, the damage was limited. No sensitive internal data was exported in bulk, and no other accounts in the organization were compromised. A small number of external recipients did click the phishing link before the client’s notification went out — which is why fast, honest communication mattered as much as the technical response.

Just as important as the technical fix was helping the client understand why it happened. This wasn’t a case of an employee being careless. She followed normal procedure, completed MFA as she always did, and had no way to know the login page wasn’t real. The gap wasn’t in her judgment — it was in the layer of protection sitting behind MFA that the organization didn’t yet have in place.

“We thought MFA meant we were covered. Farmhouse didn’t just fix the immediate problem — they showed us exactly how it happened and helped us understand what we needed to add on top of MFA to make sure it couldn’t happen again. They also helped us handle the notifications to our partners with a level head, which mattered a lot to us.”
— Executive Director, Southern Oregon nonprofit

The Takeaway for Other Organizations

Multi-factor authentication is essential — but it was never designed to stop an attacker who steals the session created after MFA succeeds. Closing that gap requires additional layers most organizations don’t realize they’re missing:

  • Conditional Access policies that restrict logins by location and device
  • Shorter session lifetimes, so a stolen session expires faster
  • The ability to revoke active sessions instantly during an incident — not just reset a password
  • Ongoing monitoring of Microsoft 365 audit logs, not just reactive review after something goes wrong

This is exactly the kind of gap our team specializes in closing — and exactly why fast, thorough forensic log review, not guesswork, made the difference in this incident.

Worried your organization has the same blind spot?

Give us a call to schedule an MFA and email-security review. We’ll show you plainly where the gaps are — before an attacker finds them first.

Call Today!

Evaluation Signup

Error: Contact form not found.

And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say,
“They share freely and give generously to the poor. Their good deeds will be remembered forever.”
For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10