Free Consultation
Case Study: Professional Services

Phishing Attack Contained
Before Any Data Left the Building

A staff member's Microsoft 365 credentials were compromised via a spoofed login page. The attacker had active access to the mailbox, but not for long.

Industry: Professional Services Location: Northern NJ Service: Cybersecurity • Managed IT

The Situation

A staff member at a small law firm received a spear-phishing email that appeared to come from a court document filing service. The email was convincing, the domain was close enough to the real service that it bypassed a quick visual check. The staff member entered their Microsoft 365 credentials on the spoofed login page.

Within hours, the attacker was inside the mailbox. They created an email forwarding rule that silently copied every incoming message to an external address. The firm had no MFA enforcement, no Microsoft 365 audit log monitoring, and no incident response plan. Without active monitoring, this could have run undetected for weeks.

What We Did

01

Detected the Anomaly Through 365 Audit Log Monitoring

Our managed services monitoring flagged the anomalous forwarding rule within hours of its creation. Microsoft 365 audit logs are part of every managed services engagement, this is exactly what they exist for.

02

Revoked Session Tokens and Locked Attacker Access

We revoked all active session tokens for the compromised account, removed the forwarding rule, and reset credentials, cutting off the attacker's access within 30 minutes of detection.

03

Audited the Mailbox for Exfiltration

We reviewed the full audit trail for the period the account was compromised. The attacker had accessed the inbox but had not opened, forwarded, or downloaded client documents. No data was exfiltrated.

04

Deployed MFA and Conditional Access Across All Accounts

Multi-factor authentication was enforced on every Microsoft 365 account in the firm. Conditional access policies now block authentication attempts from outside trusted locations and devices.

05

Conducted Firm-Wide Phishing Awareness Training

Within one week of the incident, all staff completed a phishing recognition session. Simulated phishing tests are now run quarterly as part of the managed services agreement.

The Outcome

  • Incident contained before any client data was accessed or exfiltrated
  • Attacker access revoked within 30 minutes of detection
  • MFA now enforced firm-wide, a compromised password alone can no longer open any account
  • Staff trained on phishing recognition; simulated tests run quarterly
  • Microsoft 365 audit log monitoring active across all accounts going forward
Cybersecurity Managed IT Microsoft 365 Incident Response

Work With Us

Find Out Where Your Security Gaps Are Before an Attacker Does

We audit your Microsoft 365 configuration, email security, endpoint posture, and network, and tell you exactly what needs to be fixed before an incident forces the issue.

Schedule a Security Assessment All Case Studies

Free Consultation

Talk to a Local IT Expert

Tell us about your business and we will follow up within one business day with a straight answer on how we can help.

Protected by a proof-of-work security check. No third-party tracking. Sent securely over an encrypted connection.

Frequently Asked Questions

Answers to Common Questions

What areas does Cobham Tech serve?

We are headquartered in Pottersville, New Jersey and support businesses across New Jersey, New York, Connecticut, Pennsylvania, Massachusetts, and North Carolina. Most issues are handled remotely, and we provide on-site visits throughout our New Jersey service area.

How is managed IT priced?

Managed IT is usually billed as a flat monthly fee, priced per user or per device, so your cost is predictable. The right tier depends on your size, systems, and the level of support you need. We recommend a free assessment first so any quote reflects your actual environment.

Do you require a long-term contract?

We work with businesses on both ongoing managed IT and one-time projects. We will recommend the arrangement that fits your goals rather than lock you into something you do not need. The details are always agreed on before any work begins.

Do you work with small businesses?

Yes. Much of our work is with small and mid-sized businesses that do not have a full internal IT department. We scale our support to the size of your team and the systems you rely on.

What if we already have an IT person on staff?

We can work alongside your internal staff in a co-managed model, handling monitoring, security, and after-hours coverage while your person focuses on day-to-day needs. We can also take over fully if that is a better fit.

Can you help with HIPAA or other compliance requirements?

Yes. We support medical, dental, and other regulated businesses with the technology side of compliance, including access controls, encryption, backups, and documentation. Compliance is about how your systems are configured and maintained, and that is work we do every day.

Do you provide emergency or after-hours support?

Managed IT clients have around-the-clock system monitoring and access to after-hours emergency support. If something critical happens outside business hours, you have a way to reach us rather than waiting until morning.

What kinds of businesses do you work with?

We support professional services firms, medical and dental practices, legal and financial offices, retailers, logistics companies, and nonprofits, among others. The common thread is a business that depends on its technology working and cannot afford to manage it alone.

Can you handle both our technology and our physical security?

Yes. Alongside managed IT and cybersecurity, we install and support physical security systems including cameras and access control. Bringing both under one provider keeps your digital and physical protection working together.

How do we get started?

Start with a free assessment. We review your current setup, identify what needs attention, and give you a straight answer on how we can help, with no obligation and no sales pressure. Call us at +1 315 436 1036 or request an assessment through the contact form.

See all frequently asked questions