Six Weeks After the Hack, Their Security Hadn’t Changed

Posted: September 16, 2026Category:

A small Northland business had a staff mailbox hacked. Their IT provider cleaned it up and left. Six weeks later, nothing had been added to stop it happening again.

I sat down with a small Northland engineering firm this week. About six weeks ago someone got into one of their staff mailboxes. They think it started with a dodgy click.

The attacker used that mailbox to send fake copies of the firm’s end-of-month statements to their customers. Some of them were five figures.

The attacker also set up inbox rules so any reply to those emails never reached the firm. Customers wrote back more than once & nobody in the office saw it. They found out when a customer rang to say “I think you’ve been hacked. We’ve been sent this invoice.”

Most of their customers were onto it and nobody paid. The office still lost a couple of hours going back through everyone they’d invoiced that month, resending the real invoices with a note, and ringing people.

Their IT provider came in, reset the password and found & removed the attacker’s inbox rules. Then they left.

No security was added. Nobody told the firm what should change. When we looked at their Microsoft 365 licences together this week, six weeks on, they were still on Business Standard (which can’t block an overseas login without a paid add-on) and nothing was watching for new inbox rules. If it happened again tomorrow, nothing in place would stop the sign-in or flag the rules, and they’d find out the same way – a customer on the phone.

That’s not good enough. Cleaning up after an attacker is half the job. The other half is making sure the next one can’t do the same thing, and a small business deserves that as much as a big one.

What a proper clean-up covers

A reset stops the attacker signing in with the old password. Microsoft’s own guide for a compromised mailbox has it as one step of several:

  • Sign the attacker out everywhere. Some sessions can survive a password reset until someone revokes them.
  • Delete their inbox rules & any forwarding to outside addresses. Rules sit on the mailbox, so they keep running whatever the password is.
  • Check the MFA (multi-factor authentication) methods on the account. Attackers often add their own phone so they can approve their own sign-ins.
  • Remove any app nobody recognises that has been given access to the mailbox.

Then someone should go through the sign-in & mailbox logs to see what else was opened while they were in.

That’s the clean-up. The fixes below are what stops the next one, and none of them are only for big companies.

What we’d put in place

Turn on MFA for every account first. That works on any Microsoft 365 plan.

Then move to Business Premium. Business Standard doesn’t include Conditional Access (the rules that decide who can sign in & from where) unless you buy it as an add-on. Premium has it built in. If your business sends invoices by email, you should be on Premium.

With that in place you can block sign-ins from outside New Zealand. Roughly 1 in 3 identity attacks Huntress investigates comes from a location or network the business had no reason to allow – geo-blocking stops those before the password is even tested. When someone travels, you add an exception for the trip.

The last piece is watching inbox rules. We use Huntress ITDR (identity threat detection & response), and their security team audits every new rule that gets created. Most are harmless. When one shifts mail into a folder nobody opens, like RSS Feeds, they lock the account so it can’t send any more email until it’s been sorted.

The cheapest control

If a supplier tells you their bank account has changed, pick up the phone and ring them on the number you already have. Don’t reply to the email, because the attacker may be reading it. We ask every client to set this up as an invoice fraud policy.

Ask your IT provider

If you’ve had a compromise, ask your IT provider what the attacker did while they were in, and what’s changed so it can’t happen the same way again. If the answer to the second one is “nothing”, give me a call on 09 222 7770 or have a look at our security & protection services.

Not sure where your business stands? Try the free Cyber Readiness Self-Check.

Contact us today