M365 Breach Recovery Case Study: 90 Days at a 47-Person Firm

What an M365 breach actually feels like, day by day, when it happens to a real small business.

By , CTO · Published · Last updated

TL;DR — what an M365 breach actually feels like, day by day

  • Day 0: a customer calls about a wire-instructions email the firm didn't send. The owner has 90 minutes to decide whether to panic or call the carrier.
  • Days 1–2: forensics finds a 23-day dwell time, four mailboxes with hidden forwarding rules, and one consented OAuth app reading mail since week one.
  • Days 2–7: containment, OAuth audit, Conditional Access tightening, and three surprises that nobody planned for.
  • Days 7–30: eradication, customer notification, and the awkward call about the $42,000 wire one customer already sent.
  • Days 30–90: hardening that costs about $87,000 total. The same hardening before the breach would have run $8,000 to $15,000.

A note before we start

The case below is a composite. The numbers, the timeline, and the technical findings come from real engagements. The company doesn't. Any resemblance to an actual firm is the point: this is what a typical 30-to-50-seat M365 breach looks like in 2026, and we wanted you to see it without doxxing anyone who lived through it.

For the operator-grade checklist that maps to the actions described here, see the data breach response checklist with 25 steps. For the short, urgent version when you're in hour one of an active incident, the M365 tenant compromised recovery checklist is the place to start.

Day 0: how they found out

The firm: a 47-person professional services practice in the Midwest. Three partners, four senior managers, a finance team of three, the rest are project staff and admins. Microsoft 365 Business Standard across the company. One IT generalist on contract, twelve hours a month.

On a Tuesday at 10:42 a.m., the firm's office manager picked up the phone. The caller was a long-time customer's accounts-payable lead, sounding puzzled. She'd received an email from one of the partners that morning with new wire instructions for an invoice due Friday. The email said the firm had switched banks. Could she confirm the routing and account before she queued the payment?

The office manager walked the email over to the partner. He hadn't sent it. He hadn't switched banks. The reply chain looked legitimate, threading off a real conversation from two weeks earlier. The "from" address was his, spelled correctly, no lookalike domain. The signature block was his, down to the cell-phone number.

That's how most M365 breaches get discovered in 2026. Not by an alert. Not by a SIEM. By a customer doing the right thing with a phone call. The firm had ninety minutes between that call and the next scheduled wire run on a different account, and the partner had to decide what kind of Tuesday he was about to have.

Days 1–2: the first assessment

Three things the firm did right in the first six hours:

  • The partner called the firm's cyber insurance carrier within forty minutes of the customer phone call. The carrier's hotline triaged the case to a panel forensics firm and a panel breach-coach attorney by 1:15 p.m. that afternoon. Both calls were on the books before lunch was over.
  • Nobody touched the partner's mailbox to "look around." The IT contractor was firm about that on the first call: do not log in, do not read messages, do not delete anything. Evidence preservation matters, and the carrier's forensic firm wanted the mailbox in the state it was in at discovery.
  • The finance team paused all outgoing wires for forty-eight hours. Three pending payments were flagged for verbal verification with the originating customer before release. Two were legitimate. One was the wire to a fraudulent account, caught before it left the bank.

One thing they did wrong: they waited eight hours before resetting passwords or revoking sessions. The forensics firm hadn't asked them to wait, and in retrospect the partner wished they'd hit the kill switch first thing. The attacker stayed active in the mailbox for most of Tuesday afternoon.

Forensics had preliminary findings by Wednesday evening. The story they pieced together was familiar:

  • Initial access on Day -23. The partner's password (reused from a marketing-platform breach two years prior) was tested via password spray over IMAP at 3:14 a.m. local time. Legacy auth was still on. The login succeeded. MFA was enrolled but never reached, because IMAP doesn't ask.
  • Reconnaissance through the first week. The attacker read mail, searched for the words "wire," "invoice," "ACH," and "account number," and downloaded copies of the firm's standard invoice template and the engagement letter from the customer who would later get the fraudulent wire request.
  • Persistence set up on Day -16. An inbox rule named "." (yes, a single period) moved any incoming reply containing "wire" or "verify" into a rarely-checked Archive subfolder, then forwarded a copy to [email protected], a Gmail address registered the same day, designed to look at a glance like one of the firm's own.
  • OAuth foothold on Day -14. A consent-phishing email got the partner to approve a third-party "PDF Read & Sign" app with Mail.Read and Mail.Send permissions. That app's refresh token kept reading mail right up to the morning of discovery, completely independent of the partner's password.
  • Spread over Days -10 through -3. The attacker pivoted from the partner's mailbox to set up similar inbox rules on three other mailboxes: two senior managers and the bookkeeper. Total compromised mailboxes: four.
  • Action on objectives on Days -2 through 0. Eight customers received fraudulent "updated wire instructions" emails. Six did the right thing. Two didn't.

Twenty-three days of dwell time, end to end. The forensics firm said that was on the lower end of what they see. Six to nine weeks is more typical. The customer phone call probably saved the firm three more weeks and a six-figure expansion in scope.

Days 2–7: containment, and the three surprises

Containment ran on a parallel track to the notification work. The forensics firm drove the technical containment. The breach coach drove notification timing. The firm's role was mostly logistics — making sure the right people had the right access, fielding calls from customers, keeping the partners from making it worse on Twitter.

The technical work, in order:

  1. Session revocation on the four affected accounts via Revoke-MgUserSignInSession. Refresh tokens persist for up to 90 days, and password resets alone don't kick a logged-in attacker out.
  2. Password resets on the same four accounts plus the firm's two Global Admin accounts on principle. New passwords were 32 characters, vault-stored, never reused.
  3. OAuth audit across the tenant. The "PDF Read & Sign" app was the obvious one. The forensics team also flagged a second app, "Calendar Helper Pro," consented seven months earlier by a different user, with Mail.Read scope and no apparent legitimate use. Both were revoked. Three other low-risk consents were left in place pending business owner sign-off.
  4. Inbox-rule cleanup across all 47 mailboxes, not just the four known-bad. The "." rule was on four mailboxes. A second pattern, a rule named with a single space character that auto-deleted bounced-mail notifications, was on two of those four. Without the bounce-suppression rule, the partner would have seen the failed-delivery replies from spoofed wire-fraud emails and caught the attack a week earlier.
  5. Conditional Access tightening on Day 4. The firm hadn't had a meaningful Conditional Access policy before. Day 4 brought four: block legacy auth tenant-wide, require MFA for all cloud apps, block sign-ins from anonymizing IPs, and require compliant or hybrid-joined devices for finance team members. Detailed reasoning on the legacy-auth piece is in block legacy authentication in Microsoft 365.
  6. Forwarding lockdown at the tenant level. External auto-forwarding was disabled via the anti-spam outbound policy. Existing external forwards (the firm had three legitimate ones, all now broken) were converted to mail-flow rules with explicit allow-listing.

Three surprises came up during containment that nobody had on a checklist:

  • The bookkeeper's laptop was a problem. She'd signed in with her recovered account on Wednesday morning while the forensics firm was still scoping. Token-theft malware, if any was on the laptop, would have grabbed the new session immediately. Intune wasn't deployed, so there was no clean way to wipe and re-enroll. The forensics firm pulled the laptop, imaged it, found no token-stealer, but the firm spent a tense forty-eight hours wondering if they'd just re-infected themselves.
  • One of the partners had a personal Gmail forward set up years ago for "convenience." It wasn't malicious. It also meant the firm's mail had been routinely copied to a personal Gmail account that wasn't covered by the firm's retention or security policies. The breach coach's notification scope expanded.
  • The IT contractor's admin account had no MFA. Nobody had enforced it for the contractor because "he's only here twelve hours a month." That account had Global Admin. If the attacker had pivoted to it, the entire engagement would have been a tenant-rebuild instead of a four-mailbox cleanup. The contractor was enrolled in FIDO2 keys before he went home Wednesday night.

By end of day Sunday (Day 6), containment held. The persistence hunt was repeated on Day 7 to confirm. Nothing new appeared, which is what you want.

Containment is only the first phase. The next sixty days run a different playbook: notification, recovery, and the long-term hardening that prevents the next one. The structured version is in the post-breach CIS M365 Benchmark recovery plan, with the email-side companion at the BEC prevention case study.

Days 7–30: eradication and the awkward customer calls

Eradication confirmation took until about Day 14. The forensics firm wanted two clean weekly persistence-hunt re-runs before they'd write the eradication memo. Each re-run pulled the same queries used on Day 3: OAuth grants in the last 90 days, inbox rules with forwarding or delete actions, mailbox delegations, role assignments, and audit-log activity for the affected accounts.

Restoring confidence in the four mailboxes took a different kind of work. The partners weren't sure they could trust their own Sent folders anymore. Forensics provided a timeline of every message read, sent, or forwarded by the attacker so the partners could review and confirm what was real and what wasn't. Two messages turned out to have been ghost-written by the attacker pretending to be the partner. Both were retracted with corrected versions and a short explanation.

Customer notification was where the case got most uncomfortable. Eight customers had received fraudulent wire-instruction emails. Six caught it. One delayed (caught before payment). One didn't.

That last customer had wired $42,000 to the attacker-controlled account on Day -1. Money was already in motion when the firm called Tuesday afternoon. The customer's bank was looped in within four hours. The receiving bank held the wire on Wednesday morning before final disbursement. About 60% of the funds were recovered through the carrier's incident-response retainer working with both banks. The remainder was covered under the customer's own crime policy, which had a social-engineering rider. The firm offered to make up any uninsured loss out of its own retainer with the customer. The customer's policy held, and that offer didn't have to land.

Notifications to the broader customer base went out on Day 18, after the breach coach finalized the language. The notice was direct: here's what happened, here's what we know was accessed, here's what we did, here's what we're still investigating. No spin. The press cycle was effectively zero days. One local trade publication ran a brief mention and that was the end of it.

State notifications were filed on Day 22 to the three states where affected customers resided. No HIPAA exposure. No PCI exposure. No EU residents involved, so GDPR wasn't triggered. The breach coach's rule of thumb held: counsel decides, you execute, and you don't volunteer notifications you aren't legally required to make. The full framework is in the data breach response checklist with 25 steps.

Days 30–90: hardening, and the bill

By Day 30 the firm was technically back to normal operations. By Day 90 the firm wanted to make sure the same attacker couldn't walk back in. The hardening project ran on its own track, separate from the incident, with its own budget and its own deadline of Day 90.

What got deployed:

  • Legacy auth blocked tenant-wide with both a Conditional Access policy and an Exchange Online authentication policy as backstop. The original IMAP path that started this whole thing is now closed in two independent layers.
  • Conditional Access baseline built out to about 14 policies covering risky sign-ins, device compliance, country-of-origin restrictions, and break-glass exclusions. The break-glass accounts each got a 64-character vault-stored password and were tested quarterly.
  • FIDO2 hardware keys for the three partners, the four senior managers, the IT contractor, and the three-person finance team. Eleven keys total, plus spares. The finance team in particular needed phishing-resistant MFA. Push-notification MFA wouldn't have helped against the original adversary-in-the-middle scenario the attacker eventually demonstrated against the customer.
  • Tenant-wide forwarding restrictions. External auto-forwarding disabled in the anti-spam outbound policy. Mailbox rules audited monthly. Inbox-rule creation alerts wired into the incident channel.
  • OAuth governance. User consent for non-publisher-verified apps disabled. Admin consent workflow turned on. Quarterly review of all consented apps with stale or unused ones revoked.
  • Phishing simulation program. Monthly simulated phishing emails to all staff, with a five-minute training module triggered on click. The firm hit a 2% click rate by month three, down from a baseline of 18% measured on the first run.
  • Continuous monitoring. Defender for Cloud Apps anomaly alerts wired into the IT contractor's email and a monitoring dashboard the partners review monthly.

The total cost, broken out:

  • Forensics firm: $38,000. Two senior responders, partial weeks across 30 days, plus the eradication memo and the timeline document for counsel.
  • Breach coach (counsel): $19,000. Notification drafting, regulator filings, and ongoing privilege oversight on the forensic findings.
  • Customer recovery and goodwill: $6,500. Mostly the firm's contribution to the affected customer's deductible and a small credit-monitoring offer to the broader customer base.
  • Hardening project: $23,500. Conditional Access deployment, FIDO2 keys, training program rollout, and tenant configuration to a defensible baseline.
  • Internal time: roughly $15,000 in partner and staff hours diverted from billable work over 90 days, mostly during the first three weeks.

The cyber insurance retention covered the forensics, the breach coach, and most of the customer-recovery line. Net out of pocket to the firm, after the carrier paid, was closer to $32,000. Hardening was on the firm's own dime because it was preventative work, not incident response.

A managed deployment of the same hardening before the breach would have run between $8,000 and $15,000, depending on how the FIDO2 keys were sourced and whether training was bundled. The math on prevention versus response held the way it usually does: roughly six-to-one against waiting. The cost comparison for that exact tradeoff is in the M365 security implementation case study.

The five lessons that generalize

Every breach is local. The lessons aren't. Five of them showed up in this engagement that show up in almost every M365 incident we see.

1. Speed of containment matters more than perfection of containment

The eight hours this firm waited before resetting sessions on Day 0 was the single biggest avoidable mistake in the timeline. None of the recovery plan changed because of the delay. The attacker just got eight more hours of mailbox access during the most sensitive window of the case. When in doubt, revoke first and apologize later. A reset session you didn't need to revoke is a five-minute support ticket. An attacker session you didn't revoke is a six-figure expansion.

2. The cyber insurance carrier is faster than your IT vendor

The firm's instinct was to call the IT contractor first. The carrier was the right first call. Forensics, breach coaches, and notification vendors are all on the carrier's panel and pre-priced. Going off-panel often voids reimbursement. Calling the carrier within the first hour starts a clock that benefits everyone, including the IT person, who isn't equipped to run a 60-day legal process on their own anyway.

3. MFA alone isn't enough — the attacker uses what you already have

MFA was enrolled on every account at this firm. The attacker never saw an MFA prompt because IMAP doesn't ask for one. Then they used a consented OAuth app to keep reading mail after the password reset would have kicked them out, because OAuth tokens live outside password and MFA flow. Modern attackers don't break MFA. They walk around it through the legacy protocols and the third-party app permissions you already granted. The defenses look like blocking legacy auth, locking down OAuth user consent, and moving the highest-risk accounts to phishing-resistant MFA. The full pattern is laid out in block legacy authentication in Microsoft 365.

4. Tabletops would have saved 18 hours

The firm had an IR plan on paper. Nobody had walked it. The first eight hours of Tuesday were spent figuring out who calls whom in what order, where the cyber policy number was filed, and which partner had authority to approve a six-figure forensic engagement. A two-hour tabletop, six months earlier, would have answered all of that. The hardening project added a quarterly tabletop to the calendar. The first one ran flat in 70 minutes because the team had already lived the real thing.

5. Prevention costs roughly one-sixth of response

$87,000 to recover. $8,000 to $15,000 to prevent. Those numbers are conservative. If the firm had been a HIPAA-covered entity or had EU residents in scope, the response number would have doubled or worse. The hardest part of the math, for any owner reading this case study, is that the prevention budget never produces a war story. You spend the money and nothing happens. That's the product. The owner of a 47-person firm gets to keep his Tuesdays normal.

Frequently asked questions about M365 breach recovery

Is this case study based on a real client?

It's a composite. The technical findings (23-day dwell time, the "." inbox rule, the OAuth consent app, the four-mailbox spread) are patterns we see in real engagements. The numbers ($42,000 wire, $87,000 recovery cost, 47-person firm) are representative rather than literal. We anonymized deliberately because the goal is for the reader to learn from the pattern, not to identify a specific company.

How quickly should you reset passwords once you suspect a breach?

Within the first hour, with two caveats. First, revoke the active session at the same time (Revoke-MgUserSignInSession). A password reset alone doesn't kick a logged-in attacker out. Second, if the carrier's forensic firm has been engaged and asked you to wait so they can capture live evidence, follow their direction. Outside that specific scenario, reset and revoke immediately on the affected accounts and your privileged accounts. Don't wait for "more information." The signs of compromise checklist in signs your M365 tenant is hacked is the field guide for how to spot what's happening before the customer call arrives.

What if you don't have cyber insurance when this happens?

You pay out of pocket and your options narrow. Forensics firms typically bill $250 to $500 an hour for senior responders. A 30-day engagement runs $30,000 to $80,000 for an SMB. Counsel adds $15,000 to $40,000. Notification and credit-monitoring vendors cost $5 to $15 per affected individual. A firm in this case study's footprint without insurance would have been looking at $90,000 to $150,000 cash, plus the ongoing exposure of doing the legal work without privileged guidance. If you're reading this without a policy, the most useful next step is renewing or buying one before the next quarter ends. The questionnaire is the same as the first checklist a carrier would hand you anyway.

How do you tell customers without making it worse?

Counsel writes the notice, you handle distribution. Three rules from this case that translate: be specific about what you know was accessed, be honest about what you couldn't determine, and don't speculate. Customers can hear "we don't yet know whether your specific data was viewed and we're investigating" much better than they can hear "we don't think anything happened" followed by a contradictory update three weeks later. Stand up a dedicated email alias and a phone line and route both to a person with talking points. Most press cycles end in two days when the notice is measured. Defensive notices keep the story alive for weeks.

What's the single highest-ROI control to deploy before a breach?

Blocking legacy authentication, almost every time. It costs a few hours of work and zero dollars in licensing. It eliminates the entire credential-stuffing-against-mail-protocols attack class. It would have prevented this breach outright, because the IMAP path that gave the attacker initial access wouldn't have authenticated. Phishing-resistant MFA for the finance team is the close second. FIDO2 keys for ten people is roughly $500 in hardware and an afternoon of enrollment. The full ranked list of preventative controls a 30-person business should run is in the M365 breach FAQ, with the post-breach hardening path documented in post-breach CIS M365 Benchmark recovery.

Get the free Breach Response Playbook

No spam. Unsubscribe anytime.

Find the gaps before the customer call

See what's exposed in your current M365 baseline and what it would take to close the same gaps that opened this case study's 23-day dwell time.

Check My Risk