/ BLOG
A real-life case study of a successful attack: from an email invitation to a training program to complete control over the network

At first glance, the security of modern corporate infrastructure may seem like an impregnable fortress. The Microsoft 365 cloud ecosystem, centralized management via Active Directory, multi-factor authentication (MFA), and advanced EDR systems—businesses invest significant budgets in security.
But this fortress has a weak spot: it is built and managed by people.
Even the most sophisticated technical barrier becomes meaningless if an attacker doesn’t have to search for vulnerabilities. All it takes is a timely and convincing request for a person to open the “door” from the inside.
In this case, the weak link is the human factor, and the entry point is the system administrator’s privileged account.
The Bait: How a Phishing Hook Works
In October, an employee in the IT department received an email purportedly from the corporate HR department.
The email looks convincing: branded fonts, corporate identity, a familiar tone, and a prominent “Start Training” button.
The employee clicks the button and is taken to the familiar login page for the Microsoft 365 corporate portal. Believing they need to complete a short course before the end of the year, they enter their work username and password.
A familiar MFA request arrives on their smartphone. The employee confirms the login—and seemingly gains access to the training.
In reality, attackers use an AiTM interception to obtain a legitimate session token and gain access to the Microsoft 365 account.

Why didn’t two-factor authentication work?
There is a widespread belief that having 2FA is an absolute guarantee of security. However, in this case, a real-time authentication interception technique (Adversary-in-the-Middle, AiTM) was used.
The phishing site acted as an intermediary proxy between the user and the legitimate Microsoft 365 login page and transmitted authentication data in real time. When the system administrator confirmed the second factor on their phone, the attacker’s system automatically intercepted the session token.
During such an attack, the attacker can obtain the user’s username, password, and a valid session token. Consequently, not only is the current session compromised, but the login credentials themselves are also compromised, which can be used to access other resources.
Just one compromised account—and the entire system is at risk
The attacker gained access to the company’s ecosystem. If an ordinary employee had fallen for the trap, the potential risks to the organization would have been significantly lower. However, the victim was an IT administrator.
A single compromised privileged account granted access to the following critical systems of the organization:
Corporate Email, Teams, and OneNote | Review of confidential internal correspondence, contracts, and management directives. |
Cloud storage, knowledge bases, and task management systems (SharePoint, OneDrive, Jira) | Access to project documentation, knowledge bases, and trade secrets. |
Terminal Stations (RDP/Jump Hosts) | The starting point for moving inside a closed network loop. |
Active Directory (AD) | The core of the corporate infrastructure that manages the accounts, permissions, and security policies for every workstation in the company. |
A privileged user’s actions may appear legitimate if the company does not monitor unusual activity, does not apply the principle of least privilege, and does not review administrative events.
Integration into the system and threat scenarios
Once an experienced hacker has gained these privileges, they do not immediately reveal their presence. Their main goal is to establish a stealthy foothold to carry out critical scenarios:

1. Persistence in Active Directory: Thanks to an active session token, the attacker acts on behalf of the real administrator, so the system considers him a trusted user. If he has the necessary permissions, he creates additional privileged accounts, changes access policies, and leaves himself backdoors into the network.
Changing the password may not be enough. To stop the hacker’s activity, you must separately revoke active sessions and tokens, as well as check the persistence mechanisms they have created.
2. Internal phishing: With access to the system administrator’s email, an attacker sends emails to the accounting department or top management asking them to urgently update payment details or install security updates. A message from a “colleague” raises no suspicion—and the victim follows the hacker’s instructions.
3. Exfiltration of confidential data: Over the course of several weeks, the attacker methodically copies customer databases, financial reports, and internal policies in order to later extort money or resell the data.
Assessing Business Risks in Terms of Numbers and Consequences
Risk Category | What Happens in Practice | Consequences for the Business |
Shutdown or Significant Disruption of Operations | Blocking or encryption of key servers through control over Active Directory. | Complete halt of operations, failure to meet client contract deadlines, direct financial losses. |
Reputational Damage | Leakage of customer personal data or partner databases into the public domain. | Loss of market position, termination of B2B contracts, long-term damage to reputation. |
Legal and Regulatory Sanctions | Violations of data protection requirements (GDPR, PCI DSS, industry standards). | Risk of regulatory sanctions, claims from counterparties, legal disputes, and unannounced audits—depending on the jurisdiction, nature of the data, and terms of the contracts. |
Direct financial fraud | Manipulation of accounts and payment records from trusted email accounts. | Unauthorized transfers of funds to accounts controlled by attackers. |
Security Strategy: Where Should a Manager Start?
To protect the company from such incidents, a manager does not need to delve into the technical details on their own. It is enough to oversee the implementation of five basic standards:
1. Corporate Email Security
Configure the system to automatically detect phishing attempts sent on behalf of the company and block dangerous attachments and links. Regularly verify that these settings are working properly.
2. The Principle of Least Privilege
Even senior system administrators should not have permanent and unrestricted access to the entire infrastructure. Extended access should be granted strictly for the duration of a specific technical operation (Just-In-Time access).
3. Phishing-Resistant Authentication
Standard push notifications and SMS messages are vulnerable to AiTM interception. For privileged accounts, the standard practice is to switch to hardware authentication keys (FIDO2 / Passkeys), which are technically impossible to compromise on third-party resources.
4. Anomaly Detection
Monitoring systems should flag atypical events: logins from a new device or an unusual geolocation, logins at unusual times, changes to MFA methods, the creation of new privileged accounts, or mass access to data.
5. Controlled Social Engineering Simulations
Text-based instructions alone are not enough to prepare employees for real-world attacks. Controlled and secure phishing simulations give the team the opportunity to practice the correct response to modern social engineering scenarios and improve their preparedness for attacker actions.
Key Questions for C-Level Executives
Ask your technical team just 5 questions:
1. How many employees in our company currently have global administrator privileges?
2. Are critical accounts protected by hardware keys that cannot be intercepted?
3. How will the monitoring system react if our administrator connects to the infrastructure at night from an unknown device?
4. Do employees know the clear procedure for reporting suspicious emails without fear of punishment for clicking on a link?
5. When was the last time we conducted a practical targeted phishing simulation for our team?
Identify vulnerabilities before attackers do
The security of your infrastructure isn’t just about security systems. It’s first and foremost about the people who make decisions every day: whether to open an email or ignore it, click a link or pause and verify it.
It’s better to find out how your employees will react during an attack through a controlled test than after an attacker has already breached the system. It’s always cheaper, faster, and less painful than recovering from a compromise.
Find out how this testing works and why it’s critical for protecting your company in this article.
Want to test your team’s readiness for a real hacker attack? Contact our experts to assess your cyber resilience, select an effective testing scenario, and secure your company against cyberattacks.
