I investigated an executive Microsoft 365 mailbox compromise linked to a fraudulent invoice payment. I used Azure sign-in logs and Office compliance records to establish the account timeline, identify repeated failed authentication attempts and locate the first suspicious successful sign-in in the records I reviewed.
I then examined the mailbox for a phishing message around that time. Browser-history analysis corroborated that the user had followed the suspicious link. That connected the email evidence with user activity; the failed sign-ins remained a separate observation rather than proof of the entry method.
I reviewed account changes and found an additional MFA method and mail-filtering rules. I examined Microsoft 365 audit activity for sensitive-file access and messages sent from the account to assess persistence, concealment and the visible scope of the compromise.
The known invoice-fraud conversation was the mailbox abuse identified in that review. I supported reversal of the unauthorised changes and recovery guidance, keeping the conclusion tied to the account activity available in the logs.
Closer to the work
Access and persistence
The account had suspicious successful access alongside repeated failed sign-in attempts. I investigated the access timeline, an added MFA method and mail-filtering rules. The authentication method offered a way to maintain account access; the rules could conceal relevant messages. The record does not establish a particular MFA-bypass technique.
Open this detail ↗Identity, mailbox and browser correlation
I correlated Azure sign-in timestamps with Office compliance activity, located the suspected phishing message and used browser history to corroborate interaction with its link. I then reviewed authentication-method changes, mail-filtering rules, sensitive-file activity and outbound messages to test the extent of account abuse.
Open this detail ↗Account recovery and visible scope
The known fraudulent conversation was the mailbox abuse identified in the reviewed evidence. Unauthorised account changes were reversed and the user received recovery and prevention guidance. The investigation scoped the account activity visible in the available identity and audit records.
Open this detail ↗Skills established through this work