Key facts
- Organisation
- A Singapore technology services firm
- Threat
- Business email compromise via adversary-in-the-middle (AiTM) phishing
- Initial access
- A phishing PDF forwarded from a compromised supplier; a relayed sign-in captured the session token and bypassed multi-factor authentication
- Dwell time
- About two weeks, concealed by inbox rules that hid the supplier's own security warning
- Impact
- Mailbox read (over 500 items), contacts harvested, over 800 fraud emails sent across nearly 300 recipient domains
- Core issue
- Standard multi-factor authentication can be relayed in real time; a stolen session token grants entry with no password and no fresh prompt
What this case shows
- Multi-factor authentication turns away guessed and stolen passwords, but not an attacker who relays a live sign-in as it happens.
- A trusted supplier's compromised account is a credible delivery route that sails through email filtering.
- The quiet fortnight matters more than the loud finish: the attacker used it to bury the warning and pick the thread worth impersonating.
Wondering whether an intruder is already reading one of your mailboxes? Start with a Compromise Assessment, or keep response on standby with IR-1.
What this would have cost with Blackpanda IR-1 in place
| ODIR | IR-1 | |
|---|---|---|
| Type of engagement | On-demand incident response | Yearly subscription |
| Hours covered | 20 hours | Unlimited* |
| Pricing1 | USD $10,000 | USD $1,000 |
* Unlimited for one incident per year
1 Ad-hoc incident response pricing based on average market rates, from USD 500 per hour. Blackpanda IR-1 subscription pricing based on no. of endpoints, costing approx. 10x less than ad-hoc and retainer-based incident response. All figures are illustrative only, for guidance and marketing purposes and not to be relied upon by the reader. Actual incident response costs vary by scope, complexity, and provider.
CHALLENGE
The firm ran its business the way most mid-sized technology services companies do: on a cloud mailbox, multi-factor authentication switched on, and a working trust that a login prompt answered correctly meant the right person was signing in. In April 2026 that trust turned against it. A supplier it dealt with routinely had itself been breached, and from that familiar account an attacker sent a purchase-order email with a PDF attached. A colleague forwarded the message inside the firm. A senior sales manager opened it on a work phone and tapped the link buried in the document.
No malware landed. The link walked the phone through a legitimate-looking cloud page to a counterfeit sign-in screen that sat quietly between the manager and the real service, relaying every keystroke and every approval straight through to it. This is adversary-in-the-middle (AiTM) phishing: rather than steal a password to reuse later, the attacker passes the victim's live sign-in to the genuine service in real time and pockets the session it hands back. The manager typed the password and approved the prompt. In under a minute an active session token was captured, and from that point multi-factor authentication was simply no longer in the way.
What the firm could not see was the fortnight that followed. The attacker read through the mailbox at leisure, lingering on finance and purchase-order threads, and quietly created a rule that swept the supplier's own “urgent security alert” into a folder and marked it read, so nobody saw the warning that the supplier had been compromised. For about two weeks the intruder watched, learned the firm's commercial rhythm, and waited.
SOLUTION
1. Reconstruct the intrusion and confirm the account takeover
Blackpanda pulled the mailbox and sign-in records and rebuilt the timeline from first delivery to final action. The account takeover showed the tell-tale signature of a relayed sign-in: password and prompt completed seconds apart from two different addresses, followed by one persistent session that reappeared on every later intrusion, proof the attacker replayed a single stolen session rather than beating the second factor again and again.
2. Map the reconnaissance and the hidden inbox rules
The team enumerated every message the attacker opened and every rule it created. That surfaced the rule hiding the supplier's warning and a second rule, set during the campaign, that pushed all incoming mail into an archive folder to keep returning bounce messages out of sight.
3. Scope the blast radius
Blackpanda counted the recipients of the fraud campaign, checked whether any files were touched in cloud storage, and swept the wider environment for any other compromised account. The intrusion was confined to one mailbox; no file access and no second victim account was found.
4. Contain, verify, and harden
The account was disabled, its password reset, and every active session revoked, with a “sign out everywhere” forcing the stolen token to die. Blackpanda confirmed no attacker activity after containment, including a failed attempt to sign back in days later, then handed over a hardening plan built around phishing-resistant authentication.
RESULTS
1. Entry point pinned down
The compromise traced to a single phishing PDF forwarded from a breached supplier, opened on a mobile device.
2. Scope bounded
Only one mailbox was affected; no files were accessed in cloud storage and no other account was compromised.
3. Concealment uncovered
Two malicious inbox rules and a bulk purge of over 300 items explained why the fraud left almost no trace inside the mailbox.
4. Client exposure quantified
Over 800 fraud emails reached recipients across nearly 300 domains, exposing the firm’s clients and partners to invoice- and payment-redirection fraud carried on the firm’s own good name.
5. Containment verified
Every stolen session was killed, and a later sign-in attempt from the same hosting range failed, confirming the attacker was locked out.
The thread running through all of it is that the incident was survivable because it was caught and understood, not because the perimeter held. The perimeter did not hold; a valid login walked straight past it. Organisations that treat a completed login prompt as the finish line rather than one layer, and that never rehearse how they would spot a mailbox quietly being read, are the ones for whom a case like this becomes a months-long crisis instead of a two-week clean-up.
FREQUENTLY ASKED QUESTIONS
1. If MFA was on, how did the attacker get in?
MFA was working; it was bypassed, not broken. The attacker used a fake sign-in page that relayed the manager's password and approval to the real service as they happened, then stole the logged-in session that came back. Once you hold a live session, the service no longer asks for a password or a prompt, which is why standard MFA did not stop this, and why the same pattern appeared in an earlier Singapore technology sector investigation.
2. The email came from a supplier we trust. How is that possible?
The supplier's own mailbox had been compromised first, so the lure arrived from a real, familiar account rather than a spoofed one. That is exactly what made it convincing enough to open and forward. Trusted-partner email is now one of the most effective delivery routes attackers have.
3. Was our data stolen?
The attacker read the contents of the mailbox, including finance and purchase-order correspondence, and harvested the contact details later used in the campaign. Investigators found no evidence that files were downloaded from cloud storage or that any other account was touched. What cannot be proven from logs alone is whether a specific document was read by a person, so exposed correspondence is treated as exposed.
4. Why did the phishing emails fool so many recipients?
They were sent from a genuine, authenticated mailbox and reused the subject and number of a real, in-flight purchase-order thread. Because everything checked out technically and the context looked familiar, the messages passed automated checks and read as legitimate. A comparable attack hit a Singapore media firm, where the same trusted-mailbox trick reached far further than the victim first realised.
5. What actually stops this?
Phishing-resistant authentication, such as passkeys or FIDO2 security keys bound to the real service, cannot be relayed by a fake page, which closes the exact gap used here. Pair it with policies that flag sign-ins from odd locations, shorter session lifetimes, and alerting on suspicious inbox-rule creation. If you suspect an account is already compromised, treat it as an emergency and report the incident rather than waiting to be sure.
WHAT THIS MEANS FOR YOUR ORGANISATION
Adversary-in-the-middle phishing has moved from a specialist technique to an off-the-shelf one, and it quietly rewrites the assumption most security programmes are built on: that a completed authentication prompt means a trusted user. It does not. When the attacker relays a live session, the strongest password policy and the most diligent employee still hand over the keys, and the first sign of trouble is often a flood of complaints from clients who received fraud in your name.
The practical takeaway is twofold. Move the accounts that matter to phishing-resistant sign-in, and assume that detection, not prevention alone, is what limits the damage once a session is stolen. Knowing whether an intruder is already reading a mailbox is precisely what a Compromise Assessment is for, and an IR-1 subscription puts a response team on call before the next incident becomes a crisis.
ABOUT BLACKPANDA
Blackpanda is a Lloyd’s of London–accredited insurance coverholder and Asia’s leading local cyber incident response firm, delivering end-to-end digital emergency support across the region. We are pioneering the A2I (Assurance-to-Insurance) model in cybersecurity — uniting preparation, response, and insurance into a seamless pathway that minimises financial and operational impact from cyber attack. Through expert consulting services, response assurance subscriptions, and innovative cyber insurance, we help organisations get ready, respond, and recover from cyber attacks — all delivered by local specialists working in concert.
Our mission is clear: to bring complete cyber peace of mind to every organisation in Asia, from the first moment of breach through full recovery and beyond.





