T
Lumara in Action
The Photo Lure That Hid a School Phishing Campaign
What looked like a familiar message about photos was part of a phishing campaign moving through trusted student accounts. For our SOC, the first clue was a single bounce notification.
That notification led us to high-volume phishing across multiple school environments. The messages used ordinary subject lines about photos, while mailbox rules removed sent items and replies from view. Together, the unusual sending patterns and concealed activity pointed to something wider than an isolated account compromise.
A Bounce Notification Opened the Investigation
A subject line about photos does not immediately suggest a security incident, particularly when it comes from a legitimate student account. In one case, the first visible clue was a bounce notification generated after the account sent a large volume of outbound phishing emails.
The notification led our analysts to review the timing, volume and content of the messages. They found sharp spikes in outbound activity outside normal hours and matching subject lines about photos across more than one account.
That made an isolated phishing message or unusual but legitimate student behaviour less likely. It also raised a further question: why had the account owners not noticed what was being sent from their mailboxes?
The Mailbox Rules Explained the Silence
The answer sat inside the affected mailboxes. Rules had been created to remove sent messages and incoming replies from the account owners’ view, reducing the chance that a student would see the activity and report it.
Mailbox rules are standard tools for organising email, so their presence alone does not indicate compromise. In these incidents, however, their timing and effect matched the outbound activity. The accounts sending phishing emails overnight had also been configured to conceal that activity from their owners.
Limited Endpoint Visibility Shifted Attention to the Account
The affected students were using personal devices in bring your own device (BYOD) environments. With limited endpoint telemetry available to the schools and our SOC, account and email activity became the primary evidence.
A school can monitor an account and the services it accesses without having the same visibility inside a personal device. The evidence did not establish how the accounts were initially compromised, nor did it point to a device-specific vulnerability. It did show why account-level monitoring matters when endpoint visibility is restricted.
The Same Signs Appeared Elsewhere
At that stage, the activity could still have been confined to one environment. Comparing it with other investigations showed that it was not.
Our analysts found the same combination of photo-related subject lines, overnight sending and mailbox rules that concealed activity across multiple users and organisations.
Rather than treating each mailbox as an unrelated compromise, we used the shared behaviour to investigate related activity and refine future threat hunting. Connecting those incidents gave our analysts a pattern that could guide future investigations.
The Impact Reached Beyond the Mailboxes
Phishing sent from a legitimate mailbox benefits from the trust associated with the organisation’s domain. Recipients are more likely to trust a familiar address, while sustained malicious sending can damage the domain's reputation and increase the chance that legitimate messages are filtered or rejected.
For a school, that disruption can affect communication with families, staff and external partners. The same risk applies more broadly, since one compromised account can become an operational problem for the organisation behind it.

Local Context Made the Pattern Actionable
Technical similarities alone were not enough. Our analysts checked whether users had been active, whether the messages were expected and whether local teams had observed any other unusual behaviour.
Those checks helped our SOC distinguish routine activity from connected incidents. Through Lumara, our Australian SOC can use those lessons when the same combination of unusual account activity and mailbox changes appears in another customer environment.
Account Visibility Matters When Endpoint Visibility Stops
The same visibility gap can exist in any organisation where trusted accounts are accessed through personal, lightly managed or third-party devices. Where endpoint monitoring is limited, account and email activity become more important.
Useful coverage can include alerts for unusual outbound volume, reviews of unexpected mailbox rules and prompt checks when account behaviour changes. Email gateway controls and sensible sending limits can add another layer where direct management of every device is not practical.
What began with a familiar photo lure led our analysts to the behaviour connecting incidents across multiple environments. By comparing the sending patterns, mailbox changes and local context, our SOC developed a stronger basis for recognising similar activity earlier.
Could your team connect these signals before a compromised account affected your wider organisation? See how Lumara combines continuous monitoring, human investigation and threat hunting.

