Cybersecurity

A Case Study in Identity Based Business Compromise

Written by
Net Friends Icon
Susanna Perrett

This case study is a fictional composite. Each incident is modeled on attack techniques documented in real world breaches.

Over four months, Brightwater, a regional professional services company with 350 employees, experienced three security incidents. None involved a network intrusion or software vulnerability. In each case, the attacker gained access by assuming the identity of a trusted individual.

No funds were lost, and data exposure was limited to one export of customer contact records. However, the incidents revealed that Brightwater's controls were built to keep strangers out, not to confirm that trusted identities were genuine.

Background

Brightwater operates a hybrid workforce, with 40% of staff working remotely. It relies on cloud email, a customer relationship management (CRM) platform, and multifactor authentication (MFA) for all employees.

Incident One: Executive Voice Impersonation

A caller posing as a member of the IT service desk contacted the CFO, Martin Hale, while he was traveling. The caller claimed the security team had detected suspicious sign-in attempts on his account and that his access would be suspended unless he verified his identity immediately.

The caller ID had been spoofed to display the company's internal help desk number, and the caller used the name of a real IT technician found on a professional networking site. To build credibility, the caller referenced the company's MFA provider, the CFO's current travel location from a recent social media post, and details from an old third-party data breach. The caller then asked Mr. Hale to approve an incoming MFA prompt and read back the verification code "to confirm the account belonged to him." Because the call appeared to come from an internal number and the request seemed routine, he complied.

Within twenty minutes, the attacker used the CFO's email to request an urgent payment to a new supplier. An experienced accounts payable specialist found the request out of character and called Mr. Hale directly, who confirmed he had sent nothing. No funds were transferred.

Root Cause
Verification relied on factors an attacker could publicly obtain or replicate, and the policy allowed exceptions under time pressure.
Response
Executive credential resets now require live video verification and manager confirmation, with no exceptions.

Incident Two: Fraudulent Remote Employee

Brightwater hired a remote developer presenting as Daniel Reyes, who offered a strong resume, credible references, and a solid code portfolio. His interview video was consistently poor.

The candidate had stolen the identity of a real engineer in Texas. His references were fabricated. The company laptop was shipped to an Arizona apartment that investigators later found held more than a dozen corporate laptops, each operated remotely from overseas. This mirrors publicly reported foreign job fraud schemes.

About a month in, the security team noticed the laptop using an unauthorized remote access tool and showing peak activity during overnight hours. A records review exposed inconsistencies, and the real Daniel Reyes confirmed his identity had been misused. Because the individual had access to only one project, no sensitive data was taken.

Root Cause
The hiring process verified documents but never confirmed the person presenting them was their rightful owner.
Response
Remote hires now complete identity verification in person or through an accredited third party, and equipment ships only to verified addresses.

Incident Three: Session Token Theft

The security team detected a CRM login from Romania under the account of an executive Tessa Moreno, who was asleep at home in Ohio.

Her password and MFA were intact. Instead, a shared home computer she used to send some work emails had been infected with an infostealer, delivered through unofficial gaming software a family member downloaded. The malware harvested her browser session cookies. The attacker entered her authenticated session directly, appearing to the platform as a fully trusted user.

The attacker exported customer contact records for about forty minutes before an automated impossible travel alert flagged the activity. Affected customers were notified in line with disclosure obligations.

Root Cause
Controls focused on the moment of login, while long session lifetimes and unmanaged device access let a stolen token remain usable.
Response
All sessions were revoked companywide, session lifetimes were shortened, and sensitive platforms were restricted to company managed devices.

Common Themes

Each attack exploited a different form of trust. The first relied on a familiar voice, the second on verified hiring credentials, and the third on an authenticated session. Together they span the full identity lifecycle.

All three were caught through detection rather than prevention. A colleague questioned an unusual request, an analyst noticed odd working hours, and an automated system flagged impossible travel. Behavioral monitoring and human judgment provided protection where identity verification failed.

Recommendations

Brightwater's leadership approved four measures. The company will strengthen identity verification at every stage of the employee lifecycle using methods that resist synthesized media and public data. It will treat authentication as continuous, with shorter sessions and automated responses to anomalies. It will expand targeted training for the service desk, human resources, recruiting, and finance. Finally, it will encourage employees to verify unusual requests independently, regardless of the requester's seniority.

As organizations harden networks and adopt MFA, attackers increasingly target the identities those controls protect. The central question for security leaders is no longer only how to keep strangers out, but how to confirm that the people and sessions already inside are who they claim to be.

Is your company's front door as secure as you think? Keeping strangers out is only half the battle. The real question is whether you would know if someone had already slipped inside your systems. Net Friends can help you get a firm handle on your cybersecurity. Book a meeting with one of our IT experts today and let us make sure your data stays safe.

Follow us on LinkedIn

Learn More:

How Training Impacts Identity Theft
Why Identity is the #1 Target in Cyberattacks

NetSafe MDR Stops Identity Attacks in Seconds

Take IT Off Your To-Do List.

Tech holding you back? Losing productivity to downtime?
Discover how we can simplify your tech and free up your time, contact us today.

Start a Conversation

At Net Friends, we believe in the power of human expertise. While we leverage AI to enhance our content and processes, all blog posts are written and edited by our knowledgeable staff. You can trust you are getting insights directly from our team.