CASE STUDY: Our ITDR Service Stops an Account Takeover Attempt In Minutes

ITDR icon

For this professional services firm, Identity Threat & Detection Response was the undisputed hero in hiding, swooping in to prevent a major cybersecurity threat from causing real and lasting damage.

Product: Identity Threat Detection & Response | Cyber Security
Client:
Multi-site, mid-sized business operating in professional services across Australia

The Issue: AITM Phishing Attempts

One cold winter morning, a senior staff member of a highly respected data and insights agency was targeted through a sophisticated phishing campaign designed to bypass traditional authentication controls such as Multi-Factor Authentication (MFA).

The attacker used an Adversary-in-the-Middle (AiTM) phishing technique, presenting the user with what appeared to be a legitimate Microsoft 365 login page but was in fact a decoy landing page effectively acting as a proxy between the user and the legitimate login service, relaying information back and forth in real time.

After the user entered their credentials and completed their MFA, the attacker captured the authenticated session token, granting them potential access without needing the user's password or MFA again.

This type of attack represents a growing challenge for organisations that rely solely on passwords and MFA for identity protection. Fortunately, our client had recently signed up for IT Strategic’s latest Identity Threat Detection & Response service (ITDR). 

The Incident: Attempted Session Token Theft

At approximately 7:50 AM on the day of the attack, the employee interacted with a phishing email that was later revealed to be part of a blanket attempt to target multiple users within that organisation.

Within minutes, IT Strategic's ITDR service identified suspicious behaviour associated with the user's Microsoft 365 session, looking at simultaneous anomalies and unusual signals such as:

  • Geographic location 

  • Country of origin 

  • Operating system 

  • Network infrastructure and others.

By noting inconsistencies, the activity was flagged as highly indicative of a session token theft and account compromise, triggering an instant response. 

The Response: Phishing Attack Contained in 11 Minutes

The IT Strategic team, supported by continuous identity monitoring and automated response capabilities, acted immediately to:

  • Identify the compromised session

  • Revoke active authentication sessions

  • Disable the compromised identity

  • Prevent persistence using various mechanisms

  • Review mailbox activity

  • Assess potential lateral movement and privilege exposure

  • Contain the threat before business impact occurred

  • Contact the affected user with an update 

  • Launch an investigation and remediation process.

The Impact: Threat Neutralised & Remediated

The attack window was limited to only 11 minutes, from initial compromise to attacker disablement. Because the threat was detected and contained almost immediately:

  • No evidence of sensitive data theft was identified.

  • No business systems were disrupted.

  • No ransomware activity occurred.

  • No privilege escalation was observed.

  • The attack was contained before broader organisational impact occurred.

By focusing on identity behaviour rather than authentication events alone, IT Strategic prevented a potentially significant account takeover from evolving into a wider business compromise.

Without identity-focused monitoring, a stolen session token can often remain active long enough for attackers to access email, harvest information, conduct business email compromise, or move laterally throughout the environment.

Fortunately, the attacker was unable to infiltrate further beyond the single stolen authentication token, and remediation was swiftly deployed. Crisis averted!

Learn how IT Strategic’s proactive and comprehensive approaches to IT Security and Managed Services can work to support your business. Enquire below.