Inhalte springen
Unternehmen: Banner mit Medien – Hintergrund

INC-2025-003: March 2025 Internal Sophos Phishing Attempt

Overview

In March 2025, a senior Sophos employee received a phishing email containing a fraudulent DocuSign link. This is a well-known phishing tactic, and we assess that this was non-targeted and part of a broader spam/phishing campaign. The employee clicked the link in the email, and was taken to a fake Office 365 login page, where they entered their credentials. They then received a multi-factor authentication (MFA) challenge – triggered by our legitimate MFA process – and approved it.

The threat actor, in possession of a valid session, attempted to log in to several resources, but were blocked by our Conditional Access Policy (CAP) and account limitations.

Our internal teams escalated the incident, revoked the session, and reset the employee’s credentials.

A subsequent investigation revealed that there was no suspicious activity relating to the accounts of other users who had received the email; no successful access to, or exfiltration of, documents or resources; and no further suspicious activity on the employee’s account.

Impact

The impact of this incident was limited. While the threat actor successfully obtained a valid session, they were unable to log in to corporate services due to our CAP. They were able to log in to our corporate device enrolment portal, but were unable to make any changes or register a new device, due to limited permissions (which is by design).

 

Timeline

TimeEvent
March 14, 2025 15:12 UTCInitial batch of emails received
March 14, 2025 16:04 UTCUser clicks link and inputs credentials; first malicious access attempt by attacker
March 14, 2025 16:24 UTCThe Managed Detection and Response (MDR) team investigates suspicious activity
March 14, 2025 16:26 UTCMDR escalates to Internal Detection and Response (IDR)
March 14, 2025 16:38 UTCUser reports issue
March 14, 2025 16:58 UTCIT revokes session, resets password, resets MFA
March 14, 2025 17:21 UTCThe IDR team removes remaining emails with Sophos Email clawback