acidrain
Executive Member
Hi guys,
So a strange thing has been brought to my attention. One of the company staff had sent out an email to a client with a deposit invoice attached - Invoice downloaded directly from SageOne.
This was on 20/06/2019.
A few weeks passed and the client now called the guy at the office asking when we going to start since the invoice has been paid to which he responded that he has not received any confirmation or payment. The client then sent back the email with the invoice which was only received by them on 21/06/2019 with the attached invoice. Opening the invoice you can clearly see someone photoshop'd bank details where ours use to be so the client has now paid the wrong person the deposit.
The sender on the email they received is the staff members' however they do not have this email in their sent folder with that invoice filename... the fraudulent one had additional characters added to the end of the filename.
My question, or really questions, are:
1. Is it possible that O365 mail can be intercepted? Possible malware that infected the outlook client?
2. Is there a way to check if an intercept actually happened? I know Exchange has audits but reading the results makes no sense to me.
As an interim solution I did tell them to change passwords and wipe their computer.
Cheers,
So a strange thing has been brought to my attention. One of the company staff had sent out an email to a client with a deposit invoice attached - Invoice downloaded directly from SageOne.
This was on 20/06/2019.
A few weeks passed and the client now called the guy at the office asking when we going to start since the invoice has been paid to which he responded that he has not received any confirmation or payment. The client then sent back the email with the invoice which was only received by them on 21/06/2019 with the attached invoice. Opening the invoice you can clearly see someone photoshop'd bank details where ours use to be so the client has now paid the wrong person the deposit.
The sender on the email they received is the staff members' however they do not have this email in their sent folder with that invoice filename... the fraudulent one had additional characters added to the end of the filename.
My question, or really questions, are:
1. Is it possible that O365 mail can be intercepted? Possible malware that infected the outlook client?
2. Is there a way to check if an intercept actually happened? I know Exchange has audits but reading the results makes no sense to me.
As an interim solution I did tell them to change passwords and wipe their computer.
Cheers,