T
Lumara in Action
Lumara in Action: Shutting Down a Hijacked Microsoft 365 Account
A staff email account is a trusted thing. It carries your organisation's name, sits on the safe-sender lists of every partner, supplier and customer you deal with, and people open what it sends without a second thought. That trust is exactly what makes one hijacked account so useful to an attacker.
At one of our customers, that's precisely what happened. In a single working afternoon, one staff Microsoft 365 account was taken over and turned into a phishing machine, sending hundreds of malicious messages to organisations across the country before the day was out.
If your organisation runs on Microsoft 365, the account that could do this to you already exists. It's trusted, it's in your directory, and it's one working password away from doing the same.
(Join our monthly catch-up at Cyber Coffee on Wednesday 29 July, 9:30am or 4:30pm AEST. This month we're chatting about security awareness and email security, plus the latest from the SOC desk. ☕)
It Started With a Login From Overseas
The first signal was a sign-in from a US-based IP address flagged as a VPN. An overseas login isn't proof of much on its own; people travel, and cloud accounts get reached from odd places for good reasons. What made this one matter was the context: the account had no prior overseas activity at all, which pointed to a fresh compromise rather than a travelling user.
Once inside, the attacker read through the mailbox and set up a hidden inbox rule, quietly moving incoming mail to an out-of-the-way folder and marking it read so the replies, bounce-backs and any security warnings never reached the real owner. With that in place, they sent the phishing PDF, staged in the account's own cloud storage, out to 304 recipients. 145 of those bounced or were rejected, leaving roughly 159 that may have reached someone. The list looked like the mailbox's own contact history: government, retail, finance, travel, technology, and the usual run of vendors and newsletters, almost certainly scraped from the account rather than picked with any care.
The reason it works is the address it came from. A real school account inherits the sender's reputation, and a familiar name on a known domain buys the few seconds of trust a phishing email needs. Microsoft Defender for Office 365 did flag the PDF as malicious, but by the time it did, the mail was already going out.
The Bigger Risk Was What They Read
The phishing was only the obvious half of it. While the attacker was in the mailbox they were reading it, and it held highly sensitive personal financial matters sitting alongside routine school and personal mail. That's the sort of material that lets someone come back weeks later with a targeted, believable approach, worded around something real. It didn't happen here, but it's the usual next step, which is why we advised the school to warn the affected staff member to expect targeted phishing and to change any reused passwords.
We Contained It the Same Evening
Because the environment was being watched around the clock, the sequence surfaced as it happened. Our SOC raised the incident and rang the school's IT Director directly, who agreed to disable the account straight away. It was locked within the hour. The attacker was still trying, with repeated logins from the same IP now bouncing off a "user disabled" response and another attempt about 45 minutes later, but none of them got back in. By early evening the school had run a message trace, warned staff and the executive team, and put the exposed user on notice. From the first sign of the attacker to full containment was a few hours, all inside the same day.
It's Bigger Than One Customer
This school is not an outlier. It's one example of the most expensive email problem in the country. In ASD's Annual Cyber Threat Report 2024-25, email compromise with no direct financial loss was the single most common cybercrime reported by Australian businesses at 19%, with business email compromise that did cause a loss close behind at 15%. The year before, Australians self-reported close to $84 million lost to business email compromise across more than 1,400 confirmed incidents.
The same two things show up almost every time.
The account is rarely the real target. It's a stepping stone. The value is in what the inbox can reach: the partners and customers who trust the sender, and the personal and financial detail sitting in years of mail history.
The compromise looks normal until you check what happened next. A successful login, a new inbox rule, a burst of outbound mail. Not one of them is worth a second look on its own. Put them in order and they're the whole incident, which only shows up if someone is watching for the sequence.

Most Teams Are Missing the Same Things
Most teams don't realise how exposed a single mailbox is until one is used against them. A short, honest self-audit usually settles it.
Whose accounts blend work and personal life? A work mailbox that also holds someone's tax, banking and family correspondence is a far richer target than a work-only one.
Who can log in, and from where? If sign-in isn't restricted by location, the account is reachable from every country on earth. And if a password is the only thing standing in the way, one info-stealer or phishing page is enough.
Who would notice the quiet activity after a login? A hidden inbox rule, a spike in outbound mail, a session from a country with no staff in it. The question isn't whether these leave a trace; it's whether anyone is watching closely enough to catch them in time.
A handful of controls carry most of the load.
Separate accounts for work and personal life. A work address is a higher-value target by default, and blending the two means a work compromise spills into someone's personal life, and the reverse holds too. It's the simplest habit to change and the one that shrinks the damage most.
Multi-factor authentication on every account. It won't stop everything, and token theft can still get past it, but it takes the plain "they just logged in with the password" compromise off the table.
Sign-in restricted by location. Conditional access and geographic rules take most opportunistic overseas logins out of play without getting in the way of real work.
Awareness training that shows the real lure. Someone who's seen what a phishing PDF and an unexpected "log in to view" actually look like treats them differently. An annual slideshow doesn't move the needle the same way.
None of this is exotic, and all of it helps. But even with every one of them in place, no internal team has the hours to watch every login and every new mail rule across a business, around the clock. That's the gap live detection fills.
Most Organisations Would Miss This
If a staff account at your organisation was signed in from overseas this afternoon and quietly started sending, what would the next few hours look like? Without someone watching in real time, that sign-in sits in a log no one is reading, and by the time anyone notices, the phishing has gone out under a trusted name.
For this school it went the other way. The overseas sign-in and the hidden inbox rule surfaced as they happened, Lumara Fabric correlated the scattered signals within minutes, and our 24/7 Australian SOC acted immediately, calling the IT Director directly to get the account shut down the same evening.
That's the difference live detection makes. Lumara pairs continuous monitoring with a 24/7 Australian SOC, backed by Lumara Shroud for email and communications security and Lumara Educate for the awareness that stops the click. See how it works for your environment.
If you're not sure you'd catch it, you probably wouldn't. Get in touch and we'll show you exactly what Lumara can do for your business.
Or come along to Cyber Coffee on Wednesday 29 July at 9:30am or 4:30pm AEST. We'll talk about security awareness and email security, plus everything else on the SOC desk this month. ☕

