Correlated sign-in and mailbox rule changes reveal account takeover
- Affected asset
- Entra ID and Exchange Online, user j.smith
- Rating
- High Likely 4 × High 4 = 16
Description
Correlation across identity and mail sources surfaced an account takeover that no single log made obvious: an impossible-travel sign-in from overseas, followed minutes later by the creation of an inbox rule that forwards and deletes finance mail. Neither event alone would have escalated; together they are a clear compromise, and analysts raised it within the hour.
Evidence
[identity] 08:12 sign-in j.smith from 198.51.100.7 (overseas)
prior sign-in 07:55 from Sydney (impossible travel)
[mail] 08:19 new inbox rule 'r' by j.smith:
if from contains 'invoice' -> forward ext; delete
[correlation] identity+mail within 7 min -> escalated 08:26
An impossible-travel sign-in and a suspicious mail rule, correlated within minutes, revealed a takeover in progress.
Impact
Account takeover leading to a mail-forwarding rule is the classic setup for invoice fraud, quietly redirecting finance correspondence while the user notices nothing. Catching it through correlation, within the hour, is the difference between blocking the account and explaining a fraudulent payment to the board.
Remediation
Disable the account and revoke its sessions, remove the malicious inbox rule, and review what the attacker accessed. Enforce phishing-resistant multi-factor authentication, block legacy authentication, and add a standing detection for external-forwarding rules on finance mailboxes.