On 8 April 2026, a Microsoft 365 tenant managed by Matthijssen Business Systems was investigated after suspicious account activity was reported. An automated M360 Assurance triage returned a verdict of confirmed account compromise, at maximum confidence, 34 seconds after it was started.
The following day a wider 30-day sweep was run to establish how far back the activity reached. It completed in 50 seconds and did not increase the number of critical indicators, supporting the conclusion that the compromise was confined to the period already identified.
Across 119 investigations run to date, 8 have returned a confirmed compromise. Every one of those was detected, evidenced and scoped in under a minute an average of 40 seconds.
Two triage runs were performed. The first established what had happened; the second established how far it went.
| Date | Lookback | Runtime | Verdict | Findings |
| 8 April 2026 | 7 days | 34 sec | Confirmed compromise (confidence 100) | 54 total — 3 critical, 9 high |
| 9 April 2026 | 30 days | 50 sec | Confirmed compromise (confidence 100) | 52 total — 3 critical, 8 high |
Widening the window from 7 to 30 days is a deliberate second step. It answers the question every client asks once a compromise is confirmed: how long were they in, and what else did they touch? Because the wider sweep surfaced no additional critical indicators, the scope of the incident could be stated with confidence rather than estimated.
A single triage run performs a standardised sweep that would otherwise require a technician to move between several Microsoft administrative portals, correlating evidence by hand. It examines:
Sign-in activity, including geographic anomalies and impossible-travel patterns
Failed-authentication patterns consistent with credential spraying
Mailbox rules — in particular rules created during a suspicious session
Mail-flow and transport rules, and outbound mail volume
Mailbox delegation and permission grants
OAuth application consents granted to third-party applications
Device registrations, especially newly enrolled devices
Multi-factor authentication state and changes to registered methods
The Microsoft 365 unified audit log across the investigation window
Every check is read-only. M360 Assurance reports on a tenant; it does not alter one.
Confirmed and probable compromises investigated across the managed estate have been driven by a recurring set of indicators. Individually several are unremarkable; in combination they are decisive.
| Indicator | Why it matters |
| Impossible travel | The same account authenticating from two locations too far apart to travel between in the time elapsed — strong evidence a second party holds the credentials. |
| Credential spray |
A pattern of failed sign-ins across many accounts from shared infrastructure, indicating an attempt to find any account with a weak password. |
| Inbox rule created during the session |
Attackers create rules to hide their tracks. A rule appearing during a suspicious sign-in is one of the clearest signals of hands-on-keyboard activity. |
| Stealth rules |
Rules that divert replies and warnings into rarely-opened folders such as Conversation History, so the account owner never sees the responses to messages sent in their name. |
| Abnormal outbound mail volume |
A compromised mailbox being used to send onward — typically phishing to the client’s own contacts, trading on their reputation. |
| Newly registered device |
An unfamiliar device enrolled against the account, often an attempt to establish access that survives a password reset. |
A detection service is only credible if it is also willing to say that nothing happened. Of 119 completed investigations:
| Outcome | Count | Share | Meaning |
| Confirmed compromise | 8 | 7% | Definitive evidence; immediate containment |
| Likely compromise | 20 | 17% | Strong indicators; analyst confirmation |
| Elevated suspicion | 28 | 24% | Worth investigating; not conclusive |
| No or low-confidence indicators | 63 | 53% | Cleared — reported as clean |
More than half of all investigations concluded that nothing had happened. That matters. The verdict engine is deliberately conservative: a single decisive indicator outranks a pile of weak ones, and known-good activity — such as sign-ins from Matthijssen’s own support addresses — is labelled rather than counted against the client. A report that flags everything is indistinguishable from one that flags nothing.
The interval between a credential being stolen and being used is measured in minutes. In that window an attacker reads mail, creates hiding rules, registers a device and begins sending outward. Manual investigation across Microsoft’s admin portals typically takes hours, and the evidence needed most — the audit trail — is the part that expires.
All eight confirmed-compromise investigations completed between 26 and 50 seconds. Each produced between 45 and 80 individual findings, ranked by severity, with a written verdict and a confidence score attached.
The practical effect is that containment decisions are made from evidence rather than from assumption, on the same call the issue is reported.
Detection is only the first half. Every confirmed compromise triggers the same documented response checklist, worked in order and recorded as it goes. The value of a fixed process is that nothing depends on who happens to pick up the call.
1. Contain the account
Revoke every active sign-in session, cutting off any session the attacker still holds
Reset the account password
Enable multi-factor authentication if it was not already in place
Return the account to the user only once it is secured
2. Find what the attacker left behind
A password reset alone does not end a compromise. Attackers routinely leave mechanisms that survive it, so each is checked explicitly:
3. Establish the full picture
Evidence is preserved while it is still available, and the scope of the intrusion is established rather than assumed:
4. Protect the people affected
This step matters more than it appears. The people most likely to be defrauded next are the client’s own contacts, precisely because the message genuinely came from a trusted address.
5. Reduce the chance of a repeat
That final step is deliberate. Every incident is treated as evidence about the response itself, not only about the attack.
M360 Assurance is Matthijssen Business Systems’ platform for continuous Microsoft 365 security monitoring and incident triage across its managed client base. It operates with read-only access and makes no changes to client environments.
The client in this case study has been anonymised. All figures are drawn directly from the platform’s own records — verdicts, confidence scores, timings, investigation windows and finding counts are reported exactly as recorded, and no detail has been added for effect. The response steps described are Matthijssen’s standard documented procedure for a confirmed compromise.