News & Events | Matthijssen Business Systems

M360 ASSURANCE · CLIENT CASE STUDY

Written by Praise Abraham | Sep 22, 2026, 7:13:54 PM

Anatomy of a Microsoft 365 Account Compromise


How an account takeover was detected, confirmed and scoped in under a minute

 

Summary

On 8 April 2026, a Microsoft 365 tenant managed by Matthijssen Business Systems was investigated after suspicious account activity was reported. An automated M360 Assurance triage returned a verdict of confirmed account compromise, at maximum confidence, 34 seconds after it was started.


The following day a wider 30-day sweep was run to establish how far back the activity reached. It completed in 50 seconds and did not increase the number of critical indicators, supporting the conclusion that the compromise was confined to the period already identified.


Across 119 investigations run to date, 8 have returned a confirmed compromise. Every one of those was detected, evidenced and scoped in under a minute  an average of 40 seconds.

The Investigation

Two triage runs were performed. The first established what had happened; the second established how far it went.

 

Date Lookback Runtime Verdict Findings
8 April 2026 7 days 34 sec Confirmed compromise (confidence 100) 54 total — 3 critical, 9 high
9 April 2026 30 days 50 sec Confirmed compromise (confidence 100) 52 total — 3 critical, 8 high

 

Widening the window from 7 to 30 days is a deliberate second step. It answers the question every client asks once a compromise is confirmed: how long were they in, and what else did they touch? Because the wider sweep surfaced no additional critical indicators, the scope of the incident could be stated with confidence rather than estimated.

 

What Each Investigation Examines

A single triage run performs a standardised sweep that would otherwise require a technician to move between several Microsoft administrative portals, correlating evidence by hand. It examines:

 

  • Sign-in activity, including geographic anomalies and impossible-travel patterns

  • Failed-authentication patterns consistent with credential spraying

  • Mailbox rules — in particular rules created during a suspicious session

  • Mail-flow and transport rules, and outbound mail volume

  • Mailbox delegation and permission grants

  • OAuth application consents granted to third-party applications

  • Device registrations, especially newly enrolled devices

  • Multi-factor authentication state and changes to registered methods

  • The Microsoft 365 unified audit log across the investigation window

Every check is read-only. M360 Assurance reports on a tenant; it does not alter one.

The Indicators That Matter

Confirmed and probable compromises investigated across the managed estate have been driven by a recurring set of indicators. Individually several are unremarkable; in combination they are decisive.

 

Indicator Why it matters
Impossible travel The same account authenticating from two locations too far apart to travel between in the time elapsed — strong evidence a second party holds the credentials.
Credential spray

A pattern of failed sign-ins across many accounts from shared infrastructure, indicating an attempt to find any account with a weak password.
Inbox rule created during the session

Attackers create rules to hide their tracks. A rule appearing during a suspicious sign-in is one of the clearest signals of hands-on-keyboard activity.
Stealth rules

Rules that divert replies and warnings into rarely-opened folders such as Conversation History, so the account owner never sees the responses to messages sent in their name.
Abnormal outbound mail volume

A compromised mailbox being used to send onward — typically phishing to the client’s own contacts, trading on their reputation.
Newly registered device

An unfamiliar device enrolled against the account, often an attempt to establish access that survives a password reset.

 

Results Across the Managed Estate

A detection service is only credible if it is also willing to say that nothing happened. Of 119 completed investigations:

Outcome Count Share Meaning
Confirmed compromise 8 7% Definitive evidence; immediate containment
Likely compromise 20 17% Strong indicators; analyst confirmation
Elevated suspicion 28 24% Worth investigating; not conclusive
No or low-confidence indicators 63 53% Cleared — reported as clean

 

More than half of all investigations concluded that nothing had happened. That matters. The verdict engine is deliberately conservative: a single decisive indicator outranks a pile of weak ones, and known-good activity — such as sign-ins from Matthijssen’s own support addresses — is labelled rather than counted against the client. A report that flags everything is indistinguishable from one that flags nothing.

Why Speed Is the Point

The interval between a credential being stolen and being used is measured in minutes. In that window an attacker reads mail, creates hiding rules, registers a device and begins sending outward. Manual investigation across Microsoft’s admin portals typically takes hours, and the evidence needed most — the audit trail — is the part that expires.
All eight confirmed-compromise investigations completed between 26 and 50 seconds. Each produced between 45 and 80 individual findings, ranked by severity, with a written verdict and a confidence score attached.
The practical effect is that containment decisions are made from evidence rather than from assumption, on the same call the issue is reported.

The Response

Detection is only the first half. Every confirmed compromise triggers the same documented response checklist, worked in order and recorded as it goes. The value of a fixed process is that nothing depends on who happens to pick up the call.

1. Contain the account

  • Revoke every active sign-in session, cutting off any session the attacker still holds

  • Reset the account password

  • Enable multi-factor authentication if it was not already in place

  • Return the account to the user only once it is secured

2. Find what the attacker left behind

A password reset alone does not end a compromise. Attackers routinely leave mechanisms that survive it, so each is checked explicitly:

  • Mailbox rules in Outlook and in the web client, checked separately — a rule set in one is not always visible in the other. Anything suspicious is screenshotted for the client’s records
  • Exchange connectors, which can silently reroute mail organisation-wide
  • Global Administrator membership, in case privilege was granted during the intrusion
  • Endpoint malware scan on the affected device

3. Establish the full picture

Evidence is preserved while it is still available, and the scope of the intrusion is established rather than assumed:

  • Sign-in logs exported from Microsoft Entra, extending beyond seven days where the timeline warrants it
  • Sign-in locations reviewed for activity inconsistent with the user’s normal pattern
  • Risky sign-in detections reviewed in Microsoft Entra Identity Protection
  • Message trace run to establish exactly who received mail from the account while it was under attacker control
  • A Microsoft Purview audit report covering 30, 60 or 90 days as required
  • Account search and activity history exported

4. Protect the people affected

  • Where mail was sent from the compromised account, the client is advised to contact those recipients directly, or an automated notice is issued

This step matters more than it appears. The people most likely to be defrauded next are the client’s own contacts, precisely because the message genuinely came from a trusted address.

5. Reduce the chance of a repeat

  • Managed detection and response reviewed — confirmed where already in place, offered where not
  • Phishing simulation and user training offered
  • A post-incident review is held, asking directly what could have been done better

That final step is deliberate. Every incident is treated as evidence about the response itself, not only about the attack.

 

About This Case Study

M360 Assurance is Matthijssen Business Systems’ platform for continuous Microsoft 365 security monitoring and incident triage across its managed client base. It operates with read-only access and makes no changes to client environments.

The client in this case study has been anonymised. All figures are drawn directly from the platform’s own records — verdicts, confidence scores, timings, investigation windows and finding counts are reported exactly as recorded, and no detail has been added for effect. The response steps described are Matthijssen’s standard documented procedure for a confirmed compromise.