A locked screen, emails nobody sent, and a confirmed compromise

How a frozen screen and customer phone calls turned out to be a real compromise, and what we cleaned up first.

Back to Insights
Photo: A locked screen, emails nobody sent, and a confirmed compromise

The Story

A client business rang us with two problems that turned out to be one. A staff member’s computer was stuck on a strange screen showing a QR code, and the mouse wouldn’t respond, although they could see it moving. Restarting didn’t help, and neither did unplugging it at the wall. On top of that, several of the business’s customers had called to say they’d received emails from that staff member.

The staff member hadn’t sent them.

We logged 3 hours on the response.

Two symptoms, one cause

On their own, either symptom has an innocent explanation. Computers freeze. Spam gets sent from addresses that look like yours without touching your mailbox.

Together, they point one way. A computer that won’t respond while its mouse moves by itself suggests someone else has control of it. Customers receiving emails that really came from a staff member’s account suggests that account is being used.

We asked for photos of the screen, and I spoke with the business directly. That conversation confirmed it: this was a compromise, not a glitch.

What we cleaned up

We checked the computer and found signs of compromise. From there, we:

  • cleaned up the computer
  • cleaned up the email rules on the account
  • sent an email to everyone affected
  • gave the business advice on what needed to happen next, with a quote to secure the system properly

Why email rules matter

Email rules are a favourite of attackers once they’re inside a mailbox. A rule can forward copies of incoming mail to an outside address, or quietly move replies out of the inbox so the real user never sees a customer asking “did you really send this?”

That’s why cleaning up the computer isn’t enough on its own. A rule survives a restart and a clean-up of the computer, because it lives in the mailbox.

Microsoft’s guidance on responding to a compromised email account lists suspicious inbox rules among the common symptoms, including “rules that automatically forward email to unknown addresses” and rules that move messages into folders people rarely check.

Telling the people affected

Emailing everyone who received the fake messages is uncomfortable, and it’s the right thing to do. Customers who’ve been told can ignore or delete the emails. Customers who haven’t might click a link or pay an invoice.

The business’s customers had already done it a favour by ringing. The email closed the loop for everyone else.

Where they landed

The compromise was confirmed, the computer and mailbox were cleaned up, affected contacts were told, and the business had clear advice and a quote for the work needed to secure its systems.

If a customer ever rings about an email you didn’t send, don’t wait to see if it happens again. Ring your IT provider that day, and ask them to check the mailbox’s rules and forwarding as well as the computer.

If you’d like a second opinion on how your business would handle it, get in touch.

  • The Impact of Inaction

    "Every hour a compromised mailbox stays live, it can send more emails to customers in the business's name. Rules left in place can keep hiding replies long after the computer looks normal again."

  • The Bastion Fix

    We spoke with the business and confirmed the compromise, then checked the computer and found signs of it, cleaned the computer up, removed the email rules that had been added, emailed everyone affected, and gave the business advice and a quote to secure its systems properly.

Next Action

Check every mailbox's inbox rules and forwarding settings for anything nobody remembers creating.

Teaching Moment

When customers ring about an email you didn't send, treat it as a compromise until proven otherwise. Their calls are often the first warning you'll get.

Want these results for your business?