The Wire That Never Left: What One Stolen Login Costs a Business
A CFO's Microsoft 365 account was signed into from Spain in the middle of a US business day, while password reset codes started landing in the mailbox. No wire went out. Here is what it would have cost if nobody had been watching.
A login to a CFO's Microsoft 365 account came from Spain. The company was in the United States, and it was the middle of a normal business day.
Then something else started happening. Password reset messages and one-time passcodes began arriving in that mailbox. The attacker was not just reading email. The goal was to take over the accounts behind it: the banks, the card portals, the payment systems.
Our identity monitoring caught both signals together and blocked the account automatically. Then we did the part software cannot do. We got the company on the phone and had them contact every bank and credit card provider before the attacker could change payment details, redirect payments, or send an instant wire.
No wire went out. Here is what it would have cost if we had not been watching.
The 72 Hours That Did Not Happen
Based on what we saw, the attacker was positioned to send more than $500,000 in wires. Here is what the following three days usually look like when nobody catches it.
A Scenario, Not a Record
This timeline is built from our incident. It is not a record of what happened to this client - in the real incident, the account was blocked and the banks were called before any money moved.
When
What happens without detection
What it costs
Hour 0
Attacker signs in as the CFO from another country. Nothing alerts. The account looks like it is doing its job.
CostNothing yet
Hours 1 to 4
Attacker triggers password resets at banks and payment portals, using the one-time codes that land in the mailbox the attacker now controls. The attacker changes contact numbers and payment details.
CostThe company loses control of its own accounts
Hours 4 to 24
Wires and ACH payments go out to accounts the attacker controls. Vendor payment details are changed so real invoices are paid to the wrong place. Mail rules hide the bank's alerts from the CFO.
CostMore than $500,000 in this case
Hours 24 to 48
The CFO or a vendor notices. The company calls its bank, but funds move through multiple accounts quickly, so recovery odds fall with every hour.
CostLawyers, bank fraud teams, and forensic investigators are engaged. Staff stop normal work
Hours 48 to 72
Every account the CFO touched is treated as compromised: banks, payroll, vendor portals, customer data, cloud services. Insurance carrier is notified. Legal decides whether notification duties apply.
CostDays of finance team time. Delayed payables and payroll risk. Possible notification costs and a claim that may not cover everything
The wire is only the first bill. After it come the investigation, the legal review, the finance team who spend a week reissuing credentials and re-verifying every vendor, and the deals and customers that wait while you do it. And once a claim is filed, the insurance carrier usually chooses the incident response firm - Shield Advocate is an independent owner's representative, retained by you and accountable only to you.
Why This Attack Works
The FBI's Internet Crime Complaint Center counted 24,768 business email compromise complaints in 2025, with reported losses of about $3.05 billion - the second most costly crime type it tracks. Complaints like that make up under 2.5% of cybercrime reports but nearly 15% of reported dollar losses. A small number of incidents cause an outsized share of the damage.
$3.05B
BEC losses reported in 2025
<2.5%
Share of complaints
~15%
Share of reported losses
The reason is simple. There is no virus to detect. The attacker signs in with a real password and behaves like an employee. Traditional antivirus sees nothing. What gives the attacker away is behavior: the wrong country, the wrong time, and a burst of password resets that the real user did not ask for.
What to Do Before It Happens to You
Watch sign-ins, not just devices.
Ask your provider whether anyone reviews Microsoft 365 sign-in activity around the clock. A login from Spain to a US-based CFO in the middle of a workday should be an alert in minutes, not a finding in an audit. That is what Shield ITDR is built to watch.
Alert on the password reset burst.
A run of reset and one-time code emails to one mailbox is a strong sign that someone is working through that person's accounts. So is a new inbox rule that hides mail from your bank - the kind of mailbox activity Shield Email Protection watches for.
Decide who calls the bank before you need to.
Keep a one-page list with the finance contact and after-hours number for every bank, card provider, and payment platform, and who is allowed to place a hold.
Require a call-back on any change to payment details.
Use a number you already have on file, never the one in the email. The same rule applies to your help desk: see how to verify users before a password reset.
Remove the standing wire authority you do not need.
Lower limits and dual approval turn a $500,000 loss into a blocked transaction. If nobody owns these policies today, a vCISO engagement can put them in writing.
Know the first hour.
The difference between a saved company and a costly one in this case was speed: the account was blocked and the banks were called before any money moved. Speed is the control. Have an incident response plan that names who does what in that hour.
What We Would Ask You
If your CFO's account were signed into from another country this morning, who would know, and how soon?
If the answer is "we would find out when the bank called," that is the gap.
SOClogix runs 24x7 identity monitoring for organizations that cannot afford to find out the hard way. If you want to see what your own sign-in activity looks like, talk to us about a Microsoft 365 identity risk review.
Book a ReviewSources
Business email compromise figures: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report . The report records 24,768 BEC complaints and $3,046,598,558 in BEC losses, out of 1,008,597 total complaints and $20.877 billion in total losses.
About SOClogix
SOClogix provides 24/7 managed security services to SMBs and mid-market organizations through the Shield product line - including identity and mailbox monitoring for Microsoft 365, where attacks like this one start.
Contact SOClogix
Related from SOClogix
- Shield ITDR - identity threat detection for Microsoft 365
- Shield Email Protection - mailbox monitoring
- Incident Response engagements
- Shield Advocate - your representative after a breach
- Case study: stopping a CFO account takeover before a $500,000 wire
- IR case study: tracing an M365 account lockout to a hidden foothold
- Data Breach Cost Calculator