#008UrgentSecurity fundamentalsDifficulty 3/3
User clicked a phishing link and entered credentials
Reported by Sarah Lin, Studio Manager
Intake
Sarah entered her password on a page reached from a 'shared invoice' email. Twenty minutes later a supplier received an email from her mailbox with new bank details.
Evidence gathered
- ▸Sign-in log shows a successful sign-in from an unfamiliar country minutes after the click
- ▸A new inbox rule moves messages containing 'invoice' to RSS Feeds and marks them read
- ▸Sent Items has been cleared, but the supplier has the message
- ▸MFA (Multi-Factor Authentication) was enrolled — the sign-in shows a satisfied MFA claim
Guided diagnosis
1. MFA was enrolled, yet the attacker signed in. What most likely happened?
2. What is the first containment step?
3. The inbox rule hiding 'invoice' mail tells you what?
4. What must happen outside the technical response?
5. Which prevention would have had the highest impact here?