The challenge:
A client was experiencing continual unauthorized access to their email tenant. The compromise involved unauthorized outbound communications and the creation of fraudulent accounts, presenting serious operational and financial risk including mass direct deposit fraud, fraudulent student worker activity, and phishing campaigns.
CRA approach:
CRA professionals acted swiftly to investigate the incident, maintaining clear and consistent communication with the client throughout the engagement. The team provided decisive, well-reasoned findings and practical guidance, enabling the client to understand the scope of the issue and take immediate action.
The investigation was supported by a multidisciplinary team with experience across forensic analysis, threat detection, and remediation strategy. This ensured that the client received comprehensive support, from detailed technical analysis to senior-level advice and coordination with key stakeholders.
The CRA team conducted a thorough collection and review of the available email tenant logs, identifying over 60 compromised accounts. Through detailed analysis, the team uncovered a consistent pattern of password reset emails originating from the client’s third-party single sign-on platform. Further testing and validation revealed a vulnerability that allowed threat actors to access user email accounts without requiring a password, demonstrating exceptional attention to detail and investigative rigor.
The impact:
The response prioritized limiting further exposure while protecting the institution’s operational integrity and trust. By identifying the root cause of the compromise rather than treating only the symptoms, the CRA team enabled the client to implement a targeted and efficient remediation strategy.
The team worked closely with the institution to address and resolve the vulnerability, mitigating the risk of continued unauthorized access and reducing the likelihood of future incidents—saving time, resources, and the cost of repeated investigations.


