
A Los Angeles real-estate firm.
Five compromised mailboxes in four months — then a plan that lets us act in minutes
Where they started.
A Los Angeles real-estate development and property-management firm — a few dozen staff, money moving daily — kept getting the same phone call from us: another account had been taken over. Attackers were stealing session tokens through adversary-in-the-middle phishing, replaying them from data-centre addresses, and creating mailbox rules to hide what they were doing. Each incident was contained. None of them was the last.
Key obstacles to overcome.
The hurdles they needed to clear.
The same attack, five times
Different users, identical signature: a phished session replayed from hosting infrastructure the firm's staff would never use.
MFA that could be phished
Multifactor was on, but not phishing-resistant — a relayed login passed it every time.
Nothing stopped a data-centre login
No policy distinguished a partner's laptop from an attacker's server.
Containment needed permission at 2 a.m.
Every response waited for someone senior to approve locking an account — at month-end, at night, with money in flight.
How we approached it.
A comprehensive approach to modernizing their IT infrastructure.
24/7 detection with a SOC behind it
Managed detection on the email platform: rogue mailbox rules, impossible travel and token replay raise an alert and trigger automatic session revocation.
A repeatable runbook
Every incident follows the same checklist — revoke sessions, reset credentials, remove rogue MFA methods and mailbox rules, audit sign-ins, sweep the phishing email from every mailbox.
Fix the posture, not the incident
Conditional access that blocks logins from hosting providers and unmanaged devices, legacy authentication disabled, phishing-resistant MFA on the accounts that matter.
A tabletop with leadership
A one-hour breach simulation surfaced who calls whom overnight, who talks to customers, and who talks to the insurer.
Pre-authorised containment
The outcome that mattered most: the firm authorised us in writing to lock any account, any hour, without asking first — executives included, month-end included.
Measurable impact.
Lasting results that compound over time.
Minutes to contain
Containment no longer waits for a phone tree; sessions are revoked automatically and credentials reset on our authority.
The attack path is closed
Data-centre and unmanaged-device logins are blocked at the door; a phished session no longer works.
Leadership knows the play
Named roles for overnight calls, customer and vendor communication, insurance and sensitive-data exposure — written down and rehearsed.
Gaps found first
The exercise exposed missing pieces — legal counsel, a route for customers who receive a fraudulent email, a personal-data policy — now on the firm's plan.
From incidents to a program
Incident response became part of the managed service, with the runbook, the policies and the exercise reviewed on a schedule.
Ready to transform your organization?
Let's discuss how Methodology IT can help your organization achieve similar results.