Full Report
Discover how Huntress Managed Identity Threat Detection and Response identified three business email compromise (BEC) attacks within 72 hours of each other.
Analysis Summary
# Incident Report: Multi-Client Microsoft 365 BEC Campaign
## Executive Summary
Between June 21 and June 23, 2023, a series of Business Email Compromise (BEC) attacks targeted three separate clients managed by a single MSP. The attackers leveraged credential compromise to gain access to Microsoft 365 environments, primarily using malicious inbox rules to hide their activity. Huntress Managed ITDR identified the breaches through impossible travel alerts and anomalous configuration changes, leading to rapid account lockouts that prevented financial or data loss.
## Incident Details
- **Discovery Date:** June 21 - June 23, 2023
- **Incident Date:** June 21 - June 23, 2023
- **Affected Organization:** Three unnamed clients of a single Managed Service Provider (MSP)
- **Sector:** Legal (Law Firm), Construction (Building Contractor), and Retail/Distribution
- **Geography:** United States (Specific sightings in Michigan, New York, and Virginia)
## Timeline of Events
### Initial Access
- **Date/Time:** June 21, 2023 (Case 1); June 22, 2023 (Case 2); June 23, 2023 (Case 3)
- **Vector:** Credential Compromise (likely Phishing or Credential Stuffing)
- **Details:** Attackers gained valid credentials for employee Microsoft 365 accounts.
### Lateral Movement
- **Details:** The report indicates attackers moved within the SaaS environment by manipulating account settings and permissions rather than traditional lateral movement across a local network.
### Data Exfiltration/Impact
- **Details:** In the Law Firm case, attackers targeted communications with a specific insurance company. In the Contractor case, all incoming mail was diverted, likely to facilitate invoice fraud or intercept sensitive project bids.
### Detection & Response
- **Discovery:** Detection via "Impossible Travel" alerts (e.g., login from MI and NY in quick succession) and "Anomalous Login Location" alerts (e.g., Virginia).
- **Response actions taken:** Huntress SOC issued incident reports, automatically locked out the compromised accounts, and notified the MSP partner for remediation.
## Attack Methodology
- **Initial Access:** Valid Accounts (Microsoft 365)
- **Persistence:** Manipulation of Inbox Rules (Forwarding/Redirecting to hidden folders)
- **Defense Evasion:** Redirecting emails to obscure folders like "RSS Feeds," "Deleted Items," or "Conversation History" to ensure the victim does not see notifications or replies from the attacker's targets.
- **Credential Access:** Likely obtained via prior phishing or credential harvesting.
- **Discovery:** Internal reconnaissance to identify high-value contacts (e.g., identifying auto insurance representatives).
- **Impact:** Account Takeover and Business Process Subversion (aimed at financial fraud).
## Impact Assessment
- **Financial:** Potential for high-value invoice fraud (prevented).
- **Data Breach:** Risk of sensitive legal and commercial communications being intercepted.
- **Operational:** Minimal due to rapid detection, though impacted users were temporarily locked out for security.
- **Reputational:** Potential damage to the MSP's reputation had the attacks succeeded across three clients simultaneously.
## Indicators of Compromise
- **Behavioral indicators:**
- Logins from disparate geographic locations (Michigan, New York, Virginia) within short timeframes.
- Usage of multiple distinct User Agents for a single account.
- Creation of inbox rules with suspicious names (e.g., `...` or `xx`).
- Redirection of email traffic to the `RSS Feeds` folder.
## Response Actions
- **Containment measures:** Automated account lockout.
- **Eradication steps:** Deletion of malicious inbox rules and revocation of active sessions.
- **Recovery actions:** Password resets and implementation of MFA (Multi-Factor Authentication) where missing.
## Lessons Learned
- **Key takeaways:** Attackers are increasingly using "hidden" folders like RSS Feeds to stash intercepted emails because users rarely check them.
- **What could have been done better:** The presence of multiple logins from different states suggests a lack of geo-fencing or strict conditional access policies.
## Recommendations
- **Enforce Multi-Factor Authentication (MFA):** Ensure all accounts, especially those in sensitive sectors like Law and Construction, require MFA.
- **Monitor Inbox Rules:** Implement automated monitoring for the creation of new inbox rules that move/delete messages or forward them to external addresses.
- **Conditional Access:** Restrict logins to known-good geographic regions or managed devices to prevent "impossible travel" scenarios.
- **User Training:** Educate staff on the signs of BEC and the importance of checking folder integrity if they stop receiving expected emails.