A Los Angeles real-estate firm
Cybersecurity

A Los Angeles real-estate firm.

Five compromised mailboxes in four months — then a plan that lets us act in minutes

Los Angeles, CA
25 - 50 staff
Client background

Where they started.

A Los Angeles real-estate development and property-management firm — a few dozen staff, money moving daily — kept getting the same phone call from us: another account had been taken over. Attackers were stealing session tokens through adversary-in-the-middle phishing, replaying them from data-centre addresses, and creating mailbox rules to hide what they were doing. Each incident was contained. None of them was the last.

Challenges

Key obstacles to overcome.

The hurdles they needed to clear.

The same attack, five times

Different users, identical signature: a phished session replayed from hosting infrastructure the firm's staff would never use.

MFA that could be phished

Multifactor was on, but not phishing-resistant — a relayed login passed it every time.

Nothing stopped a data-centre login

No policy distinguished a partner's laptop from an attacker's server.

Containment needed permission at 2 a.m.

Every response waited for someone senior to approve locking an account — at month-end, at night, with money in flight.

Our solution

How we approached it.

A comprehensive approach to modernizing their IT infrastructure.

24/7 detection with a SOC behind it

Managed detection on the email platform: rogue mailbox rules, impossible travel and token replay raise an alert and trigger automatic session revocation.

A repeatable runbook

Every incident follows the same checklist — revoke sessions, reset credentials, remove rogue MFA methods and mailbox rules, audit sign-ins, sweep the phishing email from every mailbox.

Fix the posture, not the incident

Conditional access that blocks logins from hosting providers and unmanaged devices, legacy authentication disabled, phishing-resistant MFA on the accounts that matter.

A tabletop with leadership

A one-hour breach simulation surfaced who calls whom overnight, who talks to customers, and who talks to the insurer.

Pre-authorised containment

The outcome that mattered most: the firm authorised us in writing to lock any account, any hour, without asking first — executives included, month-end included.

Outcomes

Measurable impact.

Lasting results that compound over time.

Minutes to contain

Containment no longer waits for a phone tree; sessions are revoked automatically and credentials reset on our authority.

The attack path is closed

Data-centre and unmanaged-device logins are blocked at the door; a phished session no longer works.

Leadership knows the play

Named roles for overnight calls, customer and vendor communication, insurance and sensitive-data exposure — written down and rehearsed.

Gaps found first

The exercise exposed missing pieces — legal counsel, a route for customers who receive a fraudulent email, a personal-data policy — now on the firm's plan.

From incidents to a program

Incident response became part of the managed service, with the runbook, the policies and the exercise reviewed on a schedule.

Ready when you are

Ready to transform your organization?

Let's discuss how Methodology IT can help your organization achieve similar results.

  • Physical Security