Skip to main content
Back to Case Studies
Identity Threat DetectionBusiness Email Compromise 2026

Stopping a CFO Account Takeover Before a $500,000 Wire

A sign-in from Spain to a US company's CFO account, followed by a burst of password reset and one-time passcode emails. The attacker was working toward the company's banks and payment systems. No wire went out.

$500K+
In wires the attacker was positioned to send
2 signals
Foreign sign-in and a password reset burst, correlated together
$0
Left the company - no wire, no redirected payment

The Alert

In the middle of a normal US business day, the Microsoft 365 account belonging to a company's CFO signed in from Spain. The company operates in the United States. On its own, a foreign sign-in can be travel or a VPN. What happened next was not.

Password reset messages and one-time passcodes began arriving in the CFO's mailbox. The attacker was not there to read email. The mailbox was the key to every account that sends its reset codes there: the banks, the card portals, the payment systems.

Detection and Response

01

Two Signals, Read Together

SOClogix identity monitoring saw the sign-in from an unexpected country and the burst of reset and one-time code emails landing in the same mailbox. Either signal alone can be noise. Together they describe an attacker working through a victim's accounts.

02

The Account Was Blocked Automatically

The correlated detection blocked the CFO's account, cutting the attacker off from the mailbox that was receiving the reset codes.

03

The Part Software Cannot Do

Blocking the mailbox does not undo a reset the attacker may already have completed at a bank. SOClogix got the company on the phone and had them contact every bank and credit card provider, so the attacker could not change payment details, redirect payments, or send an instant wire.

Key insight: There was no malware to find. The attacker signed in with a real password and behaved like an employee. What gave them away was behavior: the wrong country, the wrong time, and password resets the real user never asked for.

The Outcome

The CFO's account was blocked before the attacker could use it to take over the company's financial accounts

Every bank and credit card provider was contacted before payment details could be changed

No wire or ACH payment went out, and no vendor payment was redirected

The attacker had been positioned to send more than $500,000 in wires

Why This Case Matters

Business email compromise was the second most costly crime type the FBI's Internet Crime Complaint Center tracked in 2025, with about $3.05 billion in reported losses. Most of that damage comes from exactly this pattern: a finance executive's mailbox used as the way into the accounts that move money.

The difference between a saved company and a costly one was that someone was watching sign-ins, not just devices - and that the banks were called before any money moved. For the 72 hours this incident avoided, and six controls to put in place now, read The Wire That Never Left.

Identity Threat DetectionMicrosoft 365Business Email CompromiseWire FraudAccount TakeoverCFO Fraud

Who is watching your executives' sign-ins?

Shield ITDR monitors Microsoft 365 identities around the clock, so a sign-in like this one is caught before the bank calls you.