One Compromised Admin Account, Eight Businesses Exposed

Industry: Professional services, Civil Engineering and Mining.

Size: Eight client organisations hit by a single upstream compromise
Focus: What a real BEC interception tells you about where businesses are actually exposed

___________________________________________________________________________________________________________________

Background

This one started with a client flagging a suspicious email.

Then another did. Then another.

By the time we looked into it, eight of our clients had received the same phishing link, dressed up as a tender document, all coming from the same company. A business our clients knew and had legitimate contact with.

The company sending those emails had no idea it was happening.

___________________________________________________________________________________________________________________

What We Looked At

We needed to know three things fast:

  • How many clients were hit and from how many different inboxes
  • What level of access the attacker likely had
  • Whether anyone had already clicked

We pulled sign-in logs and built a script to search for the email across all our client environments.

It took about 15 minutes to have a clear picture.

___________________________________________________________________________________________________________________

What Was Really Happening

The attacker did not just get into one inbox. They got into the whole tenant.

Admin-level access to the email environment, most likely Microsoft 365. Every mailbox. Every contact list. Free to send from any of them, whenever they wanted.

That is why eight different clients got the same phishing link from eight different senders, all at the same company. The attacker was just working through the address book.

This is not unusual. When a business email compromise works, it almost always means someone with admin access got phished first. From there it fans out fast.

AI is making the initial phishing step easier too. The messages look real. The context is right. A tender link from a known contact is exactly the kind of thing most people open without a second thought.

The real problem here was not a clever attacker. It was that one admin credential opened the door to everything.

___________________________________________________________________________________________________________________

How Far Could It Have Gone?

Within one hour, all eight clients were protected. No successful compromises. No one had clicked through.

Here is how that happened.

A suspicious sign-in alert fired on one of our client’s mailboxes. That triggered the response. Within 15 minutes we had identified every affected client and had a script running across all environments. Within the hour the malicious link was blocked and sign-in logs had been reviewed across the board.

But here is what stays with us about this one.

The company whose system was taken over had none of that. No alerts. No separation between admin and standard accounts. They probably found out when their contacts started calling them.

That is a very different outcome, for a very similar situation.

Most businesses running a standard email setup right now are closer to that company than they are to our clients. They would find out about a compromise the same way, after the fact, from someone else.

___________________________________________________________________________________________________________________

Our top 5 tips to mitigate \ prevent your email system being compromised.

Five things. None of them are complicated.

1. MFA on every email account If a password gets stolen and there is no second factor, it is game over immediately. This one control stops the majority of account takeovers before they start.

2. Separate admin accounts from day-to-day email Your IT person should not be managing the email system through the same account they use to read their inbox. A dedicated admin account, not tied to the main domain, with only the access it actually needs. Credentials for that account go in a password manager, not a Word doc or a sticky note.

3. Behaviour & Sign In Alerts This is what caught it for our clients. Unusual location, unfamiliar device, out-of-hours access – all of it should fire an alert. Without this, you are relying on a client to tell you something is wrong.

4. Least privilege access Most people in a business have no reason to have admin access to the email system. Narrowing that down limits how far one compromised account can travel.

5. Communicate fast when something looks off The faster someone flags a suspicious email, the faster it gets contained. Every hour of silence is an hour the attacker has to keep going.

___________________________________________________________________________________________________________________

Why This Matters for Other SMEs

BEC targets smaller businesses specifically because these controls are often not in place.

usually because no one has sat down and done it yet.

One admin credential. That is all it took to reach eight businesses, hundreds of contacts, and potentially a lot worse if the alert had not fired when it did.

The attacker was not sophisticated. They did not need to be. They needed a password and an unprotected admin account. They got both.

This is simply what one intercepted incident, handled in real time, showed us about where the gaps usually sit.