Incident report
Suspicious sign-in to a finance account
Harbour & Finch LLP · Reference INC-2026-031
18 min
Contained 18 minutes after detection.
An attacker used a stolen session to sign in to one finance account. We found no
evidence that they read, copied or changed any client or financial data.
What happened
The user received a convincing phishing email that copied a Microsoft sign-in page. The page captured their session after they signed in with MFA. The attacker then used that session from another country.
Impact
- One account affected for 18 minutes
- One mailbox rule created, then removed
- No client or financial data accessed
- No reporting duty to the ICO, based on our assessment
Timeline, 4 September
- The SOC detected a sign-in to a finance team account from an unfamiliar country.
- The SOC confirmed the sign-in used a stolen session token, not the user's password.
- The SOC revoked all sessions for the account, as agreed in the response plan.
- Elmfort called your nominated contact and the user to confirm the activity was not theirs.
- Password reset and sign-in methods re-registered. Incident contained.
- Investigation found one mailbox rule created by the attacker. The rule was removed.
- Review completed with no evidence of data access. Incident closed.
Cause and response
Why it happened and what changes
Root cause
Standard MFA approves a sign-in, but it does not stop a fake sign-in page from capturing the session that follows. Phishing-resistant MFA, such as passkeys or security keys, would have blocked this attack.
What worked
- Detection within minutes of the first suspicious sign-in
- Containment within the agreed response time
- Fast confirmation from your nominated contact
Actions
| Action | Owner | Status |
|---|---|---|
| Revoke sessions, reset the password and remove the mailbox rule | SOC and Elmfort | Done |
| Search all mailboxes for the same phishing email and remove it | Elmfort | Done |
| Block sign-ins from countries where you have no staff | IT provider | Done |
| Roll out phishing-resistant MFA for finance and administrator accounts | IT provider | In progress |
| Add this phishing technique to next month's awareness training | Elmfort | Planned |
Data protection assessment. We found no evidence of access to personal
data, so we assessed this as not reportable to the Information Commissioner's Office.
Your data protection lead confirmed this decision on 5 September.
Tracking. We track the open actions in your monthly Cyber Resilience
Assurance Report until they are complete.