Business Email Compromise Case Study: How We Secured a Manchester Firm's Microsoft 365 Environment
- Jeremy Ross
- 11 minutes ago
- 2 min read
A Manchester-based professional services firm got in touch after noticing something wasn't quite right in their email environment. What sounded like a quick "can you take a look at this" call turned, within about an hour, into a full-blown business email compromise investigation. That escalation is more common than you'd think.
What is business email compromise? The problem, in this case
One compromised login was all it took. Cybercriminals got into the Microsoft 365 account, had a good look around, and then started impersonating staff to send fraudulent payment requests to the business's own contacts — the classic "urgent invoice, please pay immediately" move that's caught out far bigger companies than this one.
Digging deeper, the picture got worse. This wasn't a one-off slip — it was a few gaps stacking on top of each other:
Weak account security practices
Little to no multifactor authentication (MFA)
Device security that hadn't been properly locked down
No formal cybersecurity policy to fall back on
None of these gaps were unusual. That's rather the point — they're astonishingly common, right up until the moment they're not.
How we responded: incident containment and Microsoft 365 security recovery
We didn't mess about. This was contain-first, questions-later.
Investigated every affected mailbox to establish exactly what the attacker had touched
Removed the malicious activity and locked the compromised accounts down
Reset passwords across every affected user — not just the obvious one
Deployed multifactor authentication properly, this time
Reviewed device security and compliance settings across the business
Built out enhanced security policies so this wasn't a one-time fix
Sat down with the client and talked through the real-world risks of weak access controls, in plain English, no jargon
The outcome: a genuinely secured Microsoft 365 environment
The threat was contained before it could spread any further, and the client walked away with a genuinely secured Microsoft 365 environment — not a patched one, a properly secured one. MFA now protects every account. The team understands what "good" security habits actually look like, rather than just nodding along in a meeting and forgetting it by Friday.
Most importantly: the incident became the turning point. The moment this business stopped treating cybersecurity as a "maybe next year" line item and started treating it as the cost of staying in business.
Key takeaway: why business email compromise protection can't wait
Cybersecurity has an image problem. It gets filed under "optional extras," right alongside the fancy coffee machine, until the day it very much isn't optional. One weak login is genuinely all it takes to put an entire business's finances, reputation, and client trust on the line.
The fix is rarely expensive. The incident always is.
Worried your own Microsoft 365 environment has the same gaps? Get in touch with First Contact's IT support team in Manchester for a security review before you become the next case study.