We Travel PC ← Security at We Travel PC
CASE NOTE 001 / ACCOUNT TAKEOVER, ATTEMPTED / 6 MINUTE READ

The message came from a real company. The sign-in that followed did not.

Identifying details, timing, dollar amounts, and technical specifics may be changed or withheld to protect the people involved.

What happened

A member of the office staff at a small organization we protect received an email from a firm their business had worked with for years. It said a protected message was waiting, with a button to view it. Notifications like this arrive from legitimate services every day, and this one carried a real name, a real relationship, and no spelling mistakes.

The button led to a convincing sign-in page. It was not the real one.

What gave it away

Not the email. The email passed every surface test, because it came from the trusted firm's genuinely compromised account. What gave it away was what happened next: a sign-in attempt on the staff member's account that did not look like the staff member. Wrong place, wrong device, wrong pattern. The layer that checks every sign-in, around the clock, raised its hand.

What we checked

What we found

The password had been captured by the fake page. The attempt to use it came quickly, from infrastructure with no relationship to the staff member. The extra verification on the account did its job, the attempt failed, and the monitoring flagged it. No mailbox rules had been planted, no new sign-in methods had been added, and the activity logs showed nothing was reached.

The sender was not spoofed. A real firm's real account had been compromised, which is why every authentication check on the email passed. That detail matters: it is the version of this attack that filters alone cannot stop.

What we did

What changed afterward

Sign-in protections were strengthened across every account in the organization, not just the one involved. Sign-in policies were tightened against the specific pattern used. And the incident, anonymized, became part of how staff there are trained: the next suspicious message at that organization was forwarded to us before anyone clicked it.

What another business can learn

Real incidents. Identifying details removed. How this protection is layered is documented at wetravelpc.io. If something feels wrong at your business right now, start with what to do first, and call or text 701-306-0188.