
M365 credential stuffing stopped in 63 seconds
Partner: IT Services Provider, Arizona, US
Organization: Education, 11,000 employees, New Mexico, US
Solution: Sophos MDR, Sophos Mobile
Adversary behavior
The attacker attempts to access a Microsoft 365 account at a major public school system using credential stuffing, an identity-based attack that automatically tests credentials stolen in previous data breaches. After successfully establishing a session from an anomalous IP address, the attacker gains the same level of access as a legitimate user, creating opportunities to access email, cloud applications, and other trusted resources.
Threat detection
Sophos MDR identifies a Microsoft 365 session associated with a known application identifier previously linked to credential-stuffing campaigns. By correlating multiple signals of unauthorized access, the detection separates a likely account takeover from routine authentication behavior and immediately initiates the response process.
Automated response
Sophos MDR's AI-driven workflows rapidly validate the suspicious authentication activity as a likely account compromise. With sufficient confidence to act without manual review in this case, the system automatically responds to the detection in just 63 seconds. Sophos MDR blocks the user's sign-in and revokes active sessions, disrupting the attack before the adversary can establish persistence or expand access.
Human judgment
With the immediate threat already contained, Sophos MDR experts review the incident, validate the findings, and work directly with the customer and technology partner to complete remediation. The team provides guidance on credential resets, identity hardening, and access controls, helping reduce the likelihood of future credential-based attacks.