Containing a Microsoft 365 compromise for a care provider

The problem: A care provider spotted an unusual email reply from a staff mailbox. Nothing looked obviously broken, but the wording was wrong and the mailbox handled sensitive operational information, so the risk needed treating seriously.

How we identified it

We checked Microsoft 365 sign-in activity, mailbox rules, forwarding settings and recent account changes. An unexpected inbox rule designed to hide replies pointed to account compromise rather than a simple spoofed email.

What we did

  • Reset the affected user session and password.
  • Removed malicious mailbox rules and checked for external forwarding.
  • Reviewed sign-in logs and other high-risk accounts.
  • Tightened MFA, admin-account protection and alerting.
  • Improved payment-change and sensitive-data handling checks.

The outcome

The compromise was contained before it became a wider incident. The provider gained stronger Microsoft 365 protection, clearer alerting and a practical route for reporting suspicious messages without disrupting day-to-day care operations.

Questions? Contact us and we’ll point you in the right direction.