top of page
  • Instagram
  • Facebook
  • LinkedIn
  • YouTube

Business Email Compromise Case Study: How We Secured a Manchester Firm's Microsoft 365 Environment

  • Jeremy Ross
  • 11 minutes ago
  • 2 min read

A Manchester-based professional services firm got in touch after noticing something wasn't quite right in their email environment. What sounded like a quick "can you take a look at this" call turned, within about an hour, into a full-blown business email compromise investigation. That escalation is more common than you'd think.

What is business email compromise? The problem, in this case

One compromised login was all it took. Cybercriminals got into the Microsoft 365 account, had a good look around, and then started impersonating staff to send fraudulent payment requests to the business's own contacts — the classic "urgent invoice, please pay immediately" move that's caught out far bigger companies than this one.

Digging deeper, the picture got worse. This wasn't a one-off slip — it was a few gaps stacking on top of each other:

  • Weak account security practices

  • Little to no multifactor authentication (MFA)

  • Device security that hadn't been properly locked down

  • No formal cybersecurity policy to fall back on

None of these gaps were unusual. That's rather the point — they're astonishingly common, right up until the moment they're not.

How we responded: incident containment and Microsoft 365 security recovery

We didn't mess about. This was contain-first, questions-later.

  • Investigated every affected mailbox to establish exactly what the attacker had touched

  • Removed the malicious activity and locked the compromised accounts down

  • Reset passwords across every affected user — not just the obvious one

  • Deployed multifactor authentication properly, this time

  • Reviewed device security and compliance settings across the business

  • Built out enhanced security policies so this wasn't a one-time fix

  • Sat down with the client and talked through the real-world risks of weak access controls, in plain English, no jargon

The outcome: a genuinely secured Microsoft 365 environment

The threat was contained before it could spread any further, and the client walked away with a genuinely secured Microsoft 365 environment — not a patched one, a properly secured one. MFA now protects every account. The team understands what "good" security habits actually look like, rather than just nodding along in a meeting and forgetting it by Friday.

Most importantly: the incident became the turning point. The moment this business stopped treating cybersecurity as a "maybe next year" line item and started treating it as the cost of staying in business.

Key takeaway: why business email compromise protection can't wait

Cybersecurity has an image problem. It gets filed under "optional extras," right alongside the fancy coffee machine, until the day it very much isn't optional. One weak login is genuinely all it takes to put an entire business's finances, reputation, and client trust on the line.

The fix is rarely expensive. The incident always is.

Worried your own Microsoft 365 environment has the same gaps? Get in touch with First Contact's IT support team in Manchester for a security review before you become the next case study.

First Contact Logo.png

Interdata Ltd T/A First Contact
141a Bury New Road,
Whitefield,
Manchester,
M45 6AA

Limited Company Number: 4705700

VAT Number: 812637538

Tel: 0161 740 7400

Subscribe to our newsletter to stay updated with the latest insights, industry trends, and success stories from First Contact.

© 2025 Interdata Ltd T/A First Contact | Website by Red Saturn

Trusted Technology. Trusted Partners.

bottom of page