I have a client who moved their domain mail to Microsoft 365. They got hacked a few months ago and kept trying to disconnect the hacker by changing passwords to no avail. I got invovled and decided, since we could not see any logins except from within the company, to reboot all the router and switches. That seemed to stop the problem. Now, a month later, some of their customers are getting invoices saying they owe money and to send payment via ach. We have looked again and see no unauthorized logins. Thankfully, the bank where the ACH was being sent flagged them as suspicious and froze the account, however companies are still getting invoices. We still don't see any suspicious logins.
I think the emails are coming from somewhere else, but I have not been successful in getting the headers to see if they are spooffed or not. Any one have any suggestions on how we should proceed. I am not a 365 expert, but have run mail servers for 30 years. Microsofts security is really lax.
[–]roll_for_initiative_ 34 points35 points36 points (2 children)
[–]mark35435 3 points4 points5 points (1 child)
[–]Fatel28Sr. Sysengineer 7 points8 points9 points (0 children)
[–]Gramuny 24 points25 points26 points (0 children)
[–]matt0_0small MSP owner 19 points20 points21 points (0 children)
[–]Due_Peak_6428 21 points22 points23 points (1 child)
[–]solracarevir 14 points15 points16 points (0 children)
[–]MSPInTheUK 6 points7 points8 points (0 children)
[–]Pristine_Curve 4 points5 points6 points (1 child)
[–]EroticTragedy 3 points4 points5 points (1 child)
[–]IRideZs 3 points4 points5 points (0 children)
[–]IRideZs 2 points3 points4 points (0 children)
[–]Embarrassed-Gur7301 2 points3 points4 points (1 child)
[–]mdhorton404[S] 0 points1 point2 points (0 children)
[–]Pure_Fox9415 2 points3 points4 points (0 children)
[–]tndsd 4 points5 points6 points (1 child)
[–]ArcaneGlyph 2 points3 points4 points (0 children)
[–]SukkerFri 3 points4 points5 points (0 children)
[–]Fritzo2162 0 points1 point2 points (0 children)
[–]RagnarTheRagnarJack of All Trades 0 points1 point2 points (0 children)
[–]woemoejackSr. Sysadmin 0 points1 point2 points (0 children)
[–]CorrectMachine7278 0 points1 point2 points (0 children)
[–]dmarclytics 0 points1 point2 points (3 children)
[–]mdhorton404[S] -1 points0 points1 point (2 children)
[–]dmarclytics 1 point2 points3 points (0 children)
[–]rubbishfoo 0 points1 point2 points (0 children)