Back

Example report. The organisation and all figures are fictitious.

Elmfort Incident Report · INC-2026-031

Incident report

Suspicious sign-in to a finance account

Harbour & Finch LLP · Reference INC-2026-031

Severity
Medium
Detected
4 Sep, 08:12
Contained
4 Sep, 08:30
Status
Closed, 5 Sep
18 min
Contained 18 minutes after detection. An attacker used a stolen session to sign in to one finance account. We found no evidence that they read, copied or changed any client or financial data.

What happened

The user received a convincing phishing email that copied a Microsoft sign-in page. The page captured their session after they signed in with MFA. The attacker then used that session from another country.

Impact

  • One account affected for 18 minutes
  • One mailbox rule created, then removed
  • No client or financial data accessed
  • No reporting duty to the ICO, based on our assessment

Timeline, 4 September

  1. The SOC detected a sign-in to a finance team account from an unfamiliar country.
  2. The SOC confirmed the sign-in used a stolen session token, not the user's password.
  3. The SOC revoked all sessions for the account, as agreed in the response plan.
  4. Elmfort called your nominated contact and the user to confirm the activity was not theirs.
  5. Password reset and sign-in methods re-registered. Incident contained.
  6. Investigation found one mailbox rule created by the attacker. The rule was removed.
  7. Review completed with no evidence of data access. Incident closed.
Illustrative example. Not real customer data. Confidential Page 1 of 2
Elmfort Incident Report · INC-2026-031

Cause and response

Why it happened and what changes

Root cause

Standard MFA approves a sign-in, but it does not stop a fake sign-in page from capturing the session that follows. Phishing-resistant MFA, such as passkeys or security keys, would have blocked this attack.

What worked

  • Detection within minutes of the first suspicious sign-in
  • Containment within the agreed response time
  • Fast confirmation from your nominated contact

Actions

ActionOwnerStatus
Revoke sessions, reset the password and remove the mailbox rule SOC and Elmfort Done
Search all mailboxes for the same phishing email and remove it Elmfort Done
Block sign-ins from countries where you have no staff IT provider Done
Roll out phishing-resistant MFA for finance and administrator accounts IT provider In progress
Add this phishing technique to next month's awareness training Elmfort Planned
Data protection assessment. We found no evidence of access to personal data, so we assessed this as not reportable to the Information Commissioner's Office. Your data protection lead confirmed this decision on 5 September.
Tracking. We track the open actions in your monthly Cyber Resilience Assurance Report until they are complete.
Illustrative example. Not real customer data. Confidential Page 2 of 2