by Serguey Shinder
In February 2024 one of our credit controllers typed her password into a page that looked exactly like our email login. The next morning our monitoring flagged a sign in to her account from a country she had never visited. We did what our procedure said. We reset her password, signed her out of every session, reminded her about links in emails, and closed the ticket before lunch.
Five weeks later she mentioned, in passing, that customers had become very bad at replying. She chased overdue invoices all day, and for about a month almost nobody had answered, although several had paid. When we looked, every reply had arrived. A rule on her mailbox, created at twenty past six on the morning of the attack, took any incoming message containing the words remittance, invoice or payment, forwarded a copy to an outside address, and moved the original into a folder she had never opened.
So for five weeks after we had declared the incident closed, a stranger had received a copy of every payment conversation between our credit team and our customers. Names, amounts, purchase order numbers, who was late and by how much. Everything a person needs to write a convincing email to one of our customers about one of our invoices.
The reset had done exactly what a reset does. It ended the attacker's ability to sign in. It did nothing about anything they had arranged while they were signed in, and the rule needed no sign in at all, because it ran on our server, as her, with her permissions. We had treated a compromised account as a question of who could get in. The more important question was what had changed while they were there.
When we went through it properly, the list of things an intruder can leave behind in a mail account was longer than I expected. Rules and forwarding. An extra authentication method registered as their own. An application granted permission to read the mailbox, which keeps working after a password change. Delegated access to another mailbox. Drafts and sent items used to write to customers.
Our procedure for a compromised account is now that list, checked item by item, and the ticket cannot be closed until each line has a name against it. Automatic forwarding to outside addresses is switched off for the whole company, with a short list of approved exceptions. Any new rule that forwards mail, deletes it, or moves it to a folder nobody uses raises an alert to a person. And we wrote to the customers whose conversations had gone out, so that an unexpected email about their account would be checked before it was believed.
A password reset ends an intruder's visit. It does not undo the arrangements they made, and those were the part that hurt us.
– Serguey Asael Shinder
Leave a Reply