
INC-2025-003: March 2025 Internal Sophos Phishing Attempt
Overview
In March 2025, a senior Sophos employee received a phishing email containing a fraudulent DocuSign link. This is a well-known phishing tactic, and we assess that this was non-targeted and part of a broader spam/phishing campaign. The employee clicked the link in the email, and was taken to a fake Office 365 login page, where they entered their credentials. They then received a multi-factor authentication (MFA) challenge – triggered by our legitimate MFA process – and approved it.
The threat actor, in possession of a valid session, attempted to log in to several resources, but were blocked by our Conditional Access Policy (CAP) and account limitations.
Our internal teams escalated the incident, revoked the session, and reset the employee’s credentials.
A subsequent investigation revealed that there was no suspicious activity relating to the accounts of other users who had received the email; no successful access to, or exfiltration of, documents or resources; and no further suspicious activity on the employee’s account.
Impact
The impact of this incident was limited. While the threat actor successfully obtained a valid session, they were unable to log in to corporate services due to our CAP. They were able to log in to our corporate device enrolment portal, but were unable to make any changes or register a new device, due to limited permissions (which is by design).
Timeline
| Time | Event |
|---|---|
| March 14, 2025 15:12 UTC | Initial batch of emails received |
| March 14, 2025 16:04 UTC | User clicks link and inputs credentials; first malicious access attempt by attacker |
| March 14, 2025 16:24 UTC | The Managed Detection and Response (MDR) team investigates suspicious activity |
| March 14, 2025 16:26 UTC | MDR escalates to Internal Detection and Response (IDR) |
| March 14, 2025 16:38 UTC | User reports issue |
| March 14, 2025 16:58 UTC | IT revokes session, resets password, resets MFA |
| March 14, 2025 17:21 UTC | The IDR team removes remaining emails with Sophos Email clawback |