← Drew Fashion Studio queue
#008UrgentSecurity fundamentalsDifficulty 3/3

User clicked a phishing link and entered credentials

Reported by Sarah Lin, Studio Manager

Intake

Sarah entered her password on a page reached from a 'shared invoice' email. Twenty minutes later a supplier received an email from her mailbox with new bank details.

Evidence gathered

Guided diagnosis

1. MFA was enrolled, yet the attacker signed in. What most likely happened?

2. What is the first containment step?

3. The inbox rule hiding 'invoice' mail tells you what?

4. What must happen outside the technical response?

5. Which prevention would have had the highest impact here?