Tag
medium
advisory
Detection of O365 Email Receive and Hard Delete Takeover Behavior
5 TTPsThreat actors are suppressing evidence of account compromise by receiving and then hard-deleting emails related to sensitive banking, payroll, or credential changes within Office 365 environments.
Office 365
cloud
o365
account-takeover
payroll-fraud
exfiltration
email-security
5t
high
advisory
O365 Email Password and Payroll Compromise
2 rules 3 TTPsAttackers compromise O365 accounts and delete emails related to password resets and payroll changes, potentially redirecting payroll to attacker-controlled accounts.
Office 365
account-compromise
office365
payroll-fraud
data-destruction
2r
3t