CybersecurityMFAMicrosoft 365

Why Multifactor Authentication Is So Important

Regroove IT Consulting5 min read560 words

This is a real account of a cyberattack one of our clients experienced. Details have been changed to protect their privacy. We are sharing it because understanding what actually happened in a breach, step by step, makes the case for multifactor authentication more clearly than any statistic can.

The Attacker Accesses the Mailbox

The investigation revealed that an attacker accessed our client's email account through Outlook online using an IP address from Oregon, routed through a proxy. Once inside, the attacker spent time reading through the inbox carefully. They were not immediately destructive. They were gathering information: upcoming travel plans, flight itineraries, images of the client's driver's license, and details about pending financial transactions.

The Attacker Carries Out a Phishing Attack

Using a second IP address from Tokyo, the attacker then executed the actual fraud. Having learned enough from the mailbox to sound credible, they sent a request for updated banking information, posing as the client, to a business contact. The contact believed the request was legitimate. A substantial sum was deposited into a fraudulent account.

Both IP addresses were likely the same attacker using VPN endpoints to mask their location.

How the Attacker Got In

The investigation uncovered how the attacker had obtained the client's credentials. The inbox contained numerous password update notifications. The attacker appears to have found the client's email address on the company website, created a personal Microsoft Live account using the same address, and sent a fraudulent password reset email that appeared to come from Microsoft but actually originated from a gmx.net domain.

The client believed the email was legitimate and entered their credentials.

The attacker also configured inbox rules to route messages from the relevant business contacts to obscure folders, preventing the client from seeing the fraudulent activity taking place.

Why Multifactor Authentication Would Have Stopped This

The entire attack could have been prevented with MFA enabled on the work account. Even with the client's password in hand, the attacker could not have logged in without also having access to the client's physical device.

Microsoft 365 and Azure AD MFA support multiple authentication methods beyond passwords: approval notifications through the MS Authenticator app, text messages, hardware tokens, and biometric options. Any of these would have stopped this attack at the point of entry.

Beyond MFA

MFA is not the only protection relevant to this type of attack. Exchange Online threat protection policies add filtering that catches many phishing attempts before they reach inboxes. Training users to recognize email anomalies, such as unexpected sender domains and urgent requests involving money or banking information, reduces the likelihood that a sophisticated email gets acted on.

If you are concerned about your organization's current security posture, reach out to us. A security assessment identifies the specific gaps that matter most for your environment.

Regroove IT Consulting

Microsoft Solutions Partner specializing in Managed IT Services and Modern Work, covering Microsoft 365, Teams, SharePoint, Power Platform, and Azure. Helping organizations everywhere get lasting value from their Microsoft investment since 1993.

About Regroove →

Need help with your Microsoft environment?

We work with organizations everywhere. Tell us where you are and what you're trying to solve.

Talk to Regroove