The previous IT called it resolved. The attacker still had access.
A Montana organization lost about $70,000 to wire fraud. We were brought in 80 days later and found the attacker had never actually been locked out.

A Montana organization with fewer than ten employees, running Microsoft 365 with limited security controls and no EDR in place.
Small Business
Digital Forensics, Incident Response, Microsoft 365 Hardening, Security Awareness Training
A Montana organization with fewer than ten employees suffered a business email compromise that ended in a fraudulent wire transfer of roughly $70,000. The attacker worked through a finance mailbox, where they pushed through a bank account change on a payment that was otherwise entirely legitimate.
By the time the engagement reached us, another provider had already declared the incident closed. It was not. We were brought in to find out what actually happened, whether the attacker was still there, and to build a record the organization could take to law enforcement.
Before
The Challenge
An IT provider had already attempted to remediate the incident. Their work left persistent access in place, omitted critical logging, and altered evidence needed to understand what had actually happened.
The environment was Microsoft 365 with limited controls, minimal logging, and no EDR or modern antivirus. The incident reached our team 80 days after the initial compromise — long after the money was gone, and with open questions about whether the attacker was still inside.
Leadership needed to know three things: whether the attacker still had access, how long they had been in the environment, and whether any other accounts or systems were affected. They also needed a defensible forensic record to support law enforcement and any insurance or legal process that followed.
After
The Results
The attacker's access was fully removed, and no fraudulent payments were initiated after containment. Time to contain went from multi-week persistence to a controlled, documented closure. No compromised accounts were found beyond the original finance mailbox.
Microsoft 365 was meaningfully hardened: MFA enforced for all users, long-term logging enabled, and ITDR controls in place to react quickly to suspicious sign-ins and phishing activity.
The organization came out of it with clear evidence for law enforcement and any future insurance process — a documented timeline, the attack vector, and every action taken.
The Solution
We engaged as a new DFIR provider, scoped to the existing Microsoft 365 tenant and the compromised finance workstation: mailbox and message-level forensics, device and browser analysis, and a review of cloud sign-in activity and configuration. The priority was preserving and analyzing what evidence remained despite the previous provider's actions.
We began by collecting and analyzing PST exports and email headers from the compromised mailbox and any related accounts. We examined mailbox rules, forwarding rules, OAuth applications, and Microsoft 365 sign-in logs for signs of ongoing or lateral activity. Because evidence had been altered or missed, we leaned heavily on device and browser forensics to rebuild the timeline — browser and Outlook PST artifacts ultimately gave the clearest picture of when and how the account was accessed.
The investigation confirmed a phishing email as the entry vector and showed the attacker had access for nearly 90 days. That included more than a week of persistent access after the previous provider's cleanup, because sessions were never revoked.
Once the scope was clear, we revoked sessions, rotated credentials, and enforced multifactor authentication across all accounts. We enabled a year of logging across the relevant cloud platforms and implemented identity threat detection and response controls that automatically lock or protect an account when it is phished.
We delivered security awareness training focused specifically on business email compromise, and coordinated with law enforcement alongside the organization.
The attacker still had access for more than a week after the previous provider said the incident was closed. Sessions were never revoked.
Something here raise a question about your own setup?
Thirty minutes, no slide deck. If you're in decent shape we'll tell you that.
Schedule a call