CASE STUDY: Our ITDR Service Stops an Account Takeover Attempt In Minutes
For this professional services firm, Identity Threat & Detection Response was the undisputed hero in hiding, swooping in to prevent a major cybersecurity threat from causing real and lasting damage.
Product: Identity Threat Detection & Response | Cyber Security
Client: Multi-site, mid-sized business operating in professional services across Australia
The Issue: AITM Phishing Attempts
One cold winter morning, a senior staff member of a highly respected data and insights agency was targeted through a sophisticated phishing campaign designed to bypass traditional authentication controls such as Multi-Factor Authentication (MFA).
The attacker used an Adversary-in-the-Middle (AiTM) phishing technique, presenting the user with what appeared to be a legitimate Microsoft 365 login page but was in fact a decoy landing page effectively acting as a proxy between the user and the legitimate login service, relaying information back and forth in real time.
After the user entered their credentials and completed their MFA, the attacker captured the authenticated session token, granting them potential access without needing the user's password or MFA again.
This type of attack represents a growing challenge for organisations that rely solely on passwords and MFA for identity protection. Fortunately, our client had recently signed up for IT Strategic’s latest Identity Threat Detection & Response service (ITDR).
The Incident: Attempted Session Token Theft
At approximately 7:50 AM on the day of the attack, the employee interacted with a phishing email that was later revealed to be part of a blanket attempt to target multiple users within that organisation.
Within minutes, IT Strategic's ITDR service identified suspicious behaviour associated with the user's Microsoft 365 session, looking at simultaneous anomalies and unusual signals such as:
Geographic location
Country of origin
Operating system
Network infrastructure and others.
By noting inconsistencies, the activity was flagged as highly indicative of a session token theft and account compromise, triggering an instant response.
The Response: Phishing Attack Contained in 11 Minutes
The IT Strategic team, supported by continuous identity monitoring and automated response capabilities, acted immediately to:
Identify the compromised session
Revoke active authentication sessions
Disable the compromised identity
Prevent persistence using various mechanisms
Review mailbox activity
Assess potential lateral movement and privilege exposure
Contain the threat before business impact occurred
Contact the affected user with an update
Launch an investigation and remediation process.
The Impact: Threat Neutralised & Remediated
The attack window was limited to only 11 minutes, from initial compromise to attacker disablement. Because the threat was detected and contained almost immediately:
No evidence of sensitive data theft was identified.
No business systems were disrupted.
No ransomware activity occurred.
No privilege escalation was observed.
The attack was contained before broader organisational impact occurred.
By focusing on identity behaviour rather than authentication events alone, IT Strategic prevented a potentially significant account takeover from evolving into a wider business compromise.
Without identity-focused monitoring, a stolen session token can often remain active long enough for attackers to access email, harvest information, conduct business email compromise, or move laterally throughout the environment.
Fortunately, the attacker was unable to infiltrate further beyond the single stolen authentication token, and remediation was swiftly deployed. Crisis averted!