{"incident_id":"SEC-2026-014","detected_on":"2026-04-12T08:42:00","detected_by":"SOC alert (suspicious sign-in from new geography on M365)","severity":"medium","classification":"phishing","affected_systems":["Microsoft 365 (Exchange Online)","Azure AD"],"affected_users_estimated":3,"timeline":[{"timestamp":"2026-04-11T22:14:00","action":"Phishing email delivered to 142 mailboxes (link to credential-harvesting domain typosquatting our SSO portal)."},{"timestamp":"2026-04-12T07:51:00","action":"User Sophie Martens reports suspicious email to it-security@acme-supplies.eu."},{"timestamp":"2026-04-12T08:18:00","action":"Mail-flow rule deployed to quarantine remaining copies of the message."},{"timestamp":"2026-04-12T08:42:00","action":"SOC alert: anomalous sign-in to M365 from a Lagos IP for user account p.leroy@acme-supplies.eu — credential entered on the phishing page."},{"timestamp":"2026-04-12T08:47:00","action":"Account p.leroy disabled in Azure AD; active sessions revoked."},{"timestamp":"2026-04-12T08:55:00","action":"Audit logs reviewed for the affected account — single sign-in, no mailbox rules created, no items downloaded, no OAuth grants issued."},{"timestamp":"2026-04-12T09:30:00","action":"Two further click-throughs (s.willems, k.de_smet) identified via proxy logs; both reported the email after clicking but before entering credentials. Accounts forced through password reset and MFA re-enrolment as a precaution."},{"timestamp":"2026-04-12T11:15:00","action":"Company-wide notice issued; phishing-awareness mini-module assigned to the 142 recipients."},{"timestamp":"2026-04-12T15:00:00","action":"Incident closed; post-incident actions tracked in Jira PIR-SEC-2026-014."}],"initial_assessment":"Targeted credential-phishing campaign using a typosquatted lookalike of our SSO domain. One credential confirmed entered; no evidence of mailbox compromise, data exfiltration, or lateral movement.","containment_actions":["Compromised account disabled and active sessions revoked within 6 minutes of confirmation.","Mail-flow rule deployed to quarantine remaining copies of the phishing message.","Domain added to corporate DNS sinkhole and reported to Cloudflare for takedown."],"eradication_actions":["Forced password reset + MFA re-enrolment for the 3 confirmed-clicked users.","Conditional Access policy tightened: sign-in from outside EU/EEA requires step-up MFA.","Inbound mail rule added: quarantine messages whose link domain is a typosquat of acme-supplies.eu (Levenshtein ≤ 2)."],"recovery_actions":["Re-enabled the affected account after password reset, MFA re-enrolment, and audit-log clearance.","Verified no inbox rules, no OAuth grants, no token-theft indicators present at re-enable."],"root_cause":"User clicked a phishing link and entered credentials on a typosquatted domain. Existing MFA prevented mailbox access — sign-in was blocked at the second factor, generating the SOC alert.","lessons_learned":["MFA worked as designed — credential alone did not yield account access.","User reporting was fast (within 90 minutes of the message being sent), enabling rapid mail-flow quarantine.","Conditional Access for non-EU sign-ins was not yet enforced; gap closed during eradication."],"gdpr_notifiable":false,"post_incident_owner":"Marie Laurent (CISO/DPO)","closed_on":"2026-04-12"}