Is it possible to intercept an O365 mail?

acidrain

Executive Member
Joined
Jan 7, 2007
Messages
7,004
Reaction score
1,797
Location
At a computer
Hi guys,

So a strange thing has been brought to my attention. One of the company staff had sent out an email to a client with a deposit invoice attached - Invoice downloaded directly from SageOne.

This was on 20/06/2019.

A few weeks passed and the client now called the guy at the office asking when we going to start since the invoice has been paid to which he responded that he has not received any confirmation or payment. The client then sent back the email with the invoice which was only received by them on 21/06/2019 with the attached invoice. Opening the invoice you can clearly see someone photoshop'd bank details where ours use to be so the client has now paid the wrong person the deposit.

The sender on the email they received is the staff members' however they do not have this email in their sent folder with that invoice filename... the fraudulent one had additional characters added to the end of the filename.

My question, or really questions, are:
1. Is it possible that O365 mail can be intercepted? Possible malware that infected the outlook client?
2. Is there a way to check if an intercept actually happened? I know Exchange has audits but reading the results makes no sense to me.

As an interim solution I did tell them to change passwords and wipe their computer.

Cheers,
 
I suspect that the recipients account has been compromised, with rewrite rule created.
Check the headers of the email that was received with the modified / altered attachment.
 
I’m also curious why the client didn’t send the invoice to your staff as this would have been found out quickly.. more so if I paid for a service.

Also if the original email with the correct invoice is in your staffs email address and the client didn’t receive the email, then it’s the clients problem and a security issue on their side.
 
Had client that had compromised account, the guys created rules and saved the mails under RSS feeds.

Use Message Trace to see if the mail was really composed from mailbox.
 
Last edited:
Hi guys,

So a strange thing has been brought to my attention. One of the company staff had sent out an email to a client with a deposit invoice attached - Invoice downloaded directly from SageOne.

This was on 20/06/2019.

A few weeks passed and the client now called the guy at the office asking when we going to start since the invoice has been paid to which he responded that he has not received any confirmation or payment. The client then sent back the email with the invoice which was only received by them on 21/06/2019 with the attached invoice. Opening the invoice you can clearly see someone photoshop'd bank details where ours use to be so the client has now paid the wrong person the deposit.

The sender on the email they received is the staff members' however they do not have this email in their sent folder with that invoice filename... the fraudulent one had additional characters added to the end of the filename.

My question, or really questions, are:
1. Is it possible that O365 mail can be intercepted? Possible malware that infected the outlook client?
2. Is there a way to check if an intercept actually happened? I know Exchange has audits but reading the results makes no sense to me.

As an interim solution I did tell them to change passwords and wipe their computer.

Cheers,

It may be some sort of social engineering attack. It sounds similar to an incident I saw recently where an attacker using a gmail account appeared to have masqueraded as both an orders clerk and the customer and communicated with both side as a man in the middle over a couple of days.

I have seen in the past a few instances where attackers using social engineering attacks are quite brazen in communicating back and forth with their victims and eliciting more useful information before the target smells a rat.

We always think of cyber crime in terms of hacking and technical attacks but in many respects, humans are the weakest link.
 
We've investigated many of these incidents where companies have been conned out of large amounts by making payments into third party bank accounts after the original invoices were intercepted, altered and sent to the intended recipient.

The headers will give you all the info you need, along with logs from the recipients mail server.
You can also trace the original mail from Microsoft's Security and Compliance Center and use these to help the receivers ISP nail it down
https://docs.microsoft.com/en-us/office365/securitycompliance/message-trace-scc

I suspect a certain ISP that runs cpanel without any bruteforce detection being the party that hosts the recipients mail.
 
Thanks guys.

I will ask the client to send the headers for us to look at.

I'm actually quite surprised how they managed to get fooled since it was quite obvious and they are a home loans financing house.
 
Top
Sign up to the MyBroadband newsletter
X