Customer Experiences: 123 Days in the Shadow of the Attack
Customer Experiences

123 Days in the Shadow of the Attack

When the initial analysis indicates a “two-day incident,” but in reality it’s a four-month-long breach. Here is the story of an investigation in which we traced the origins of a cyberattack, reconstructed its course minute by minute, and prepared a comprehensive report for the client—a report that served as the basis for further regulatory, legal, and operational decisions, including continuous SOC monitoring.

When the initial analysis indicates a “two-day incident,” but in reality it’s a four-month-long breach. Here is the story of an investigation in which we traced the origins of a cyberattack, reconstructed its course minute by minute, and prepared a comprehensive report for the client—a report that served as the basis for further regulatory, legal, and operational decisions, including continuous SOC monitoring.

Toward the end of 2025, we received a call from a client—an international industrial and service group operating on three continents. It is a holding company comprising more than a dozen subsidiaries active across multiple economic sectors, with a total workforce of more than a dozen thousand employees. One of the group’s companies—a small but crucial financial and legal firm in the Channel Islands—was facing a serious problem.

Hundreds of phishing emails were sent from the company CEO’s Microsoft 365 email account. The recipients were clients, partners, and business associates: investment banks, law firms, and trust funds. The holding company’s cybersecurity team conducted a preliminary analysis and summed it up in a single sentence: “A two-day incident, account secured, case closed.” However, the company’s leadership wasn’t entirely convinced. And rightly so.

Why did they come to us?

The region of the world where the client operates, as well as the Channel Islands, presents a unique environment—multiple jurisdictions, different time zones, limited access to equipment, IT teams spread across several countries, and decisions made at the corporate level. Added to this are the requirements typical of the offshore finance sector—law firms serving trusts and funds demand discretion and precision in every detail.

The client’s internal team did a good job with their initial response—they quickly suspended the account, reset the password, and implemented multi-factor authentication. However, their report only answered the question, “What happened that day?” It did not address the key questions: “How did this happen, and when did it start?”

They needed someone who would dig deeper. They chose All for One Poland for this task.

What we found changed our understanding of the situation

When we began analyzing the logs—over 90,000 events from Microsoft 365, another 9,000 from Microsoft Purview, and 20 days of network logs—we quickly discovered that the story didn’t begin in November. It began in July. Four months earlier.

The client’s internal report mentioned two days. Our analysis revealed that the attacker had 123 days of uninterrupted access to the company president’s email account, SharePoint, and OneDrive.

The tools are available to everyone. The ability to ask the right questions, the refusal to settle for easy answers, and the patience to correlate thousands of events determine whether a report will end up on a shelf or change an organization’s security policy.

Mateusz Włodarczak, Cybersecurity Consultant, All for One Poland

The Anatomy of an Attack

The attacker was no amateur. He was methodical, patient, and had a thorough understanding of how Microsoft 365 works. We reconstructed the attack step by step:

July, Day 0: Theft of Credentials

The victim receives a convincing-looking email notifying them of a voicemail. Clicking the link triggers a multi-step redirection through a legitimate marketing platform, which then leads to the real Microsoft login page—but via an intermediary that intercepts data in transit, known as an “evil proxy.” The login credentials were intercepted within 8 minutes. None of the 91 antivirus engines on VirusTotal flagged this URL as malicious.

July–October: 16 weeks of silence

The attacker read the victim’s email several times a month, from various IP addresses, using hosting infrastructure on three continents. He never logged in again; he maintained the same OAuth session for four months thanks to silent token refresh. Zero alerts, zero suspicious logins, zero anomalies.

November: Escalation

The attacker moved from reading emails to browsing documents on the corporate SharePoint: trust agreements, legal documents, and client financial data. Eight hours of nighttime email reconnaissance. The next morning, the attack.

Day of the attack: 2 hours between 7:00 a.m. and 9:00 a.m.

A hidden mailbox rule, an attempt to exfiltrate 83 files from OneDrive (blocked by the tenant policy; the only control that worked), followed by 353 phishing emails sent to business partners, including global banks and law firms. Finally: active social engineering—a real-time response to a question from a law firm partner.

The client’s IT team’s response

Within two hours: the rule was disabled, the password was reset, and all sessions were terminated. This response was exemplary. It was the termination of the sessions—not the password reset itself—that broke the token refresh chain.

Key finding: lack of MFA

And now for the most important part: what really sets our analysis apart from the previous one.

A preliminary report suggested that the attacker had hijacked session cookies, bypassing multi-factor security measures. It sounds dangerous and high-tech. But that wasn’t true.

During our on-site visit, while speaking directly with the team, we determined that at the time of the attack, the victim’s account did not have multi-factor authentication (MFA) enabled. None at all. A password and username—that was the sole security measure for the account of the managing director of a law firm handling trusts worth millions.

The attacker had access to sophisticated infrastructure capable of intercepting MFA tokens in real time. He didn’t need to use it; a password was enough.

We confirmed this finding using seven independent lines of evidence, ranging from authentication timestamps in audit logs to an analysis of the attacker’s browser digital fingerprint (a version of Chrome that had been frozen for 48 days, while the victim’s legitimate browser had undergone six updates), all the way to recovering the original phishing email from the Deleted Items folder four months after the attack.

That’s how we found this needle in a haystack. An original phishing email from July, still sitting in the trash.

How We Did It

Our methodology consisted of three phases. The first involved several weeks of remote log analysis, parsing tens of thousands of audit events, correlating IP addresses from five VPS providers, and identifying the attacker’s signatures. Even at this stage, we knew that the breach had begun much earlier than November.

But logs aren’t everything. We needed equipment.

In the second phase, our two-person team flew to the site, an island in the English Channel. Two days of intensive on-site work: disk images as evidence, extraction of data from three computers and one iPhone (98 GB of encrypted backup data, over 184,000 files), verification of the firewall configuration, and discussions with the on-site team.

And it was there, on the last day of our visit, when we already had enough correlative evidence to know exactly what to look for, that we sat down at the victim’s laptop, opened her email inbox in the browser, and found that email. A classic phishing email. Piece of evidence number one.

Phase Three: Correlation of all lines of evidence and reconstruction of the full attack chain, minute by minute.

The phishing attack on an All for One customer:
By the Numbers

22

Evidence, thoroughness, completeness

What sets us apart in this type of service is our approach.

First, a clear distinction between what has been proven and what is assumed. We do not write, “The attacker likely intercepted the MFA token,” unless we have hard evidence to support it. In this case, the earlier analysis did exactly that—it assumed the presence of MFA and, based on that, constructed a narrative about an advanced bypass. We checked. There was no MFA. This changes the entire risk assessment and all recommendations.

Second, curiosity. We don’t stop at “the account has been compromised.” We look for the initial attack vector. How? When? Why this particular victim? In this case, the answer was: a spear-phishing email posing as a voicemail notification, sent from a compromised domain, routed through a legitimate platform (which is why it passed through the filters), leading to a proxy infrastructure that then redirects to the Microsoft login page. The full chain from click to data compromise.

Third, comprehensiveness. We examined four devices, countless days’ worth of network logs, two sets of audit logs, 126,000 text messages, and 51,000 instant messages. And when we concluded, “The devices are clean,” we added—as always—one more sentence: “The absence of evidence is not evidence of the absence of a threat.” That is why we recommended rebuilding the devices from scratch.

Result: full report

Our report is over 50 pages long and includes a minute-by-minute reconstruction of the attack, an inventory of evidence, a table of compromise indicators, and 22 specific recommendations. This is something the client didn’t have before: the full picture.

Not a “two-day incident,” but 123 days of systematic reconnaissance. Not an “advanced bypass of MFA,” but a lack of basic controls on a critical account. Not “likely phishing,” but a specific email, a specific time, and a specific mechanism.

This provided the client with a basis for making the right decisions—regulatory, legal, and operational—ranging from FIDO2 hardware keys to conditional access policies to the implementation of continuous SOC monitoring.

Applications

01

Incydent nigdy nie jest tym, na co wygląda na pierwszy rzut oka.

Dwudniowy incydent okazał się czteromiesięcznym włamaniem. Warto zainwestować w dogłębną analizę, zanim zamknie się sprawę.

02

MFA to nie talizman

Samo wdrożenie standardowego uwierzytelniania wieloskładnikowego nie chroni przed nowoczesnymi atakami klasy Adversary-in-the-Middle. A jego brak na koncie uprzywilejowanym to otwarte zaproszenie. Klucze sprzętowe FIDO2 to jedyna metoda odporna na tego typu ataki.

03

Atakujący pracuje cierpliwie

Szesnaście tygodni czytania poczty dyrektora zarządzającego bez jednego alertu. Jeśli nikt nie patrzy, nikt nie zobaczy.

04

Wiedza ekspercka robi różnicę

Narzędzia są dostępne dla każdego. Umiejętność zadania właściwego pytania, odmowa przyjęcia łatwej odpowiedzi i cierpliwość w korelacji tysięcy zdarzeń decydują o tym, czy raport trafi na półkę, czy zmieni politykę bezpieczeństwa organizacji.

We’re proud of this case not because the attack was spectacular, but because no one else uncovered the truth. We uncovered it, proved it, and provided the client with a complete answer. That’s what we’re here for.

All client data has been anonymized. Technical details have been altered to the extent necessary to protect the client’s identity, while maintaining the accuracy of the investigation’s course and its conclusions.

Previous: Polmor: SAP in the All for One Private Cloud
Write us Call us Send email






    Details regarding the processing of personal data are available in the Privacy Policy

    +48 61 827 70 00

    The office is open
    Monday to Friday
    from 8am to 4pm (CET)

    General contact for the company
    office.pl@all-for-one.com

    Question about products and services
    info.pl@all-for-one.com

    Question about work and internships
    kariera@all-for-one.com

    This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.