Weird thing on O365 account
-
When I try to send to her in Outlook on the web, it shows the above, even though I've modified the user list back to her real name.
-
She likely has a fubar'd contact in one of her devices.
-
Maybe her account was hacked. Send her an email and see if it goes straight to deleted.
-
@scottalanmiller said in Weird thing on O365 account:
Maybe her account was hacked. Send her an email and see if it goes straight to deleted.
That's probable, but the number showing up in the 'to' field is from the contacts.
-
This was definitely hacked. It may have been a coincidence that they went to Jamaica at the same time.
You'll want to revoke any login tokens and check for any forwarding rules, reset the password, and check for inbox rules. Pitch them MFA.
-
@coliver said in Weird thing on O365 account:
This was definitely hacked. It may have been a coincidence that they went to Jamaica at the same time.
You'll want to revoke any login tokens and check for any forwarding rules, reset the password, and check for inbox rules. Pitch them MFA.
That's what I was thinking.
-
Sounds exactly like O365 accounts we've seen hacked in the past.
-
@scottalanmiller said in Weird thing on O365 account:
Maybe her account was hacked. Send her an email and see if it goes straight to deleted.
OK, that would make sense.
-
@coliver said in Weird thing on O365 account:
This was definitely hacked. It may have been a coincidence that they went to Jamaica at the same time.
You'll want to revoke any login tokens and check for any forwarding rules, reset the password, and check for inbox rules. Pitch them MFA.
Thanks!
-
Yep, hacked
-
@coliver said in Weird thing on O365 account:
Pitch them MFA.
Nah. Just set it up, and say its security in place so you wont get hacked again.
No pitch needed, just do it.
-
@IRJ said in Weird thing on O365 account:
@coliver said in Weird thing on O365 account:
Pitch them MFA.
Nah. Just set it up, and say its security in place so you wont get hacked again.
No pitch needed, just do it.
I don't have that level of authority, I'm an IT consultant for them, nothing more.
I have a meeting with them tonight (the whole company actually - some training stuff), but in light of this SECOND hack - I'm seriously thinking I ditch all of my current conversation and talk about password managers and 2FA only.
-
@Dashrender said in Weird thing on O365 account:
@IRJ said in Weird thing on O365 account:
@coliver said in Weird thing on O365 account:
Pitch them MFA.
Nah. Just set it up, and say its security in place so you wont get hacked again.
No pitch needed, just do it.
I don't have that level of authority, I'm an IT consultant for them, nothing more.
I have a meeting with them tonight (the whole company actually - some training stuff), but in light of this SECOND hack - I'm seriously thinking I ditch all of my current conversation and talk about password managers and 2FA only.
Second hack? Then you didn't do your job the first time.
There is really no discussion. Its a must have and they could lose their Office 365 account otherwise. Their account already has a poor reputation with Microsoft.
It's not a conversation, it's you do this or a drop you as a client
-
@IRJ said in Weird thing on O365 account:
@Dashrender said in Weird thing on O365 account:
@IRJ said in Weird thing on O365 account:
@coliver said in Weird thing on O365 account:
Pitch them MFA.
Nah. Just set it up, and say its security in place so you wont get hacked again.
No pitch needed, just do it.
I don't have that level of authority, I'm an IT consultant for them, nothing more.
I have a meeting with them tonight (the whole company actually - some training stuff), but in light of this SECOND hack - I'm seriously thinking I ditch all of my current conversation and talk about password managers and 2FA only.
Second hack? Then you didn't do your job the first time.
There is really no discussion. Its a must have and they could lose their Office 365 account otherwise. Their account already has a poor reputation with Microsoft.
It's not a conversation, it's you do this or a drop you as a client
Huh - that's the first time I've ever heard that... Thanks, the ammo is worth while.. I'll let you ya'll know what they say tomorrow.
-
-
@coliver said in Weird thing on O365 account:
This was definitely hacked. It may have been a coincidence that they went to Jamaica at the same time.
You'll want to revoke any login tokens and check for any forwarding rules, reset the password, and check for inbox rules. Pitch them MFA.
What he said. Been there done that several times. Even had someone reply to an email from the compromised account asking "Is this really you?"........ The response was of course "Yes it is me"........ Whoops there goes another account.
-
@IRJ said in Weird thing on O365 account:
Second hack? Then you didn't do your job the first time.
Security is THEIR job, not his. They are the CIO, not him. You can't blame people down the chain for the decision makers making bad decisions.
-
@Dashrender said in Weird thing on O365 account:
@IRJ said in Weird thing on O365 account:
@Dashrender said in Weird thing on O365 account:
@IRJ said in Weird thing on O365 account:
@coliver said in Weird thing on O365 account:
Pitch them MFA.
Nah. Just set it up, and say its security in place so you wont get hacked again.
No pitch needed, just do it.
I don't have that level of authority, I'm an IT consultant for them, nothing more.
I have a meeting with them tonight (the whole company actually - some training stuff), but in light of this SECOND hack - I'm seriously thinking I ditch all of my current conversation and talk about password managers and 2FA only.
Second hack? Then you didn't do your job the first time.
There is really no discussion. Its a must have and they could lose their Office 365 account otherwise. Their account already has a poor reputation with Microsoft.
It's not a conversation, it's you do this or a drop you as a client
Huh - that's the first time I've ever heard that... Thanks, the ammo is worth while.. I'll let you ya'll know what they say tomorrow.
How do we know that their account has a poor reputation? You can look that up. We've had accounts disabled for poor reputation and never tied to being hacked, always tied to bad employees (yes we fired people.) It's unlikely that they have a bad reputation unless MS told you so.
-
@scottalanmiller said in Weird thing on O365 account:
@IRJ said in Weird thing on O365 account:
Second hack? Then you didn't do your job the first time.
Security is THEIR job, not his. They are the CIO, not him. You can't blame people down the chain for the decision makers making bad decisions.
What world are you living in? This is how 99.99999% of IT lives, getting blamed for other peoples bad decision making.
-
@Dashrender Anybody notify Accounting of these fraudent emails being forwarded to them?