A client business rang us with two problems that turned out to be one. A staff member’s computer was stuck on a strange screen showing a QR code, and the mouse wouldn’t respond, although they could see it moving. Restarting didn’t help, and neither did unplugging it at the wall. On top of that, several of the business’s customers had called to say they’d received emails from that staff member.
The staff member hadn’t sent them.
We logged 3 hours on the response.
Two symptoms, one cause
On their own, either symptom has an innocent explanation. Computers freeze. Spam gets sent from addresses that look like yours without touching your mailbox.
Together, they point one way. A computer that won’t respond while its mouse moves by itself suggests someone else has control of it. Customers receiving emails that really came from a staff member’s account suggests that account is being used.
We asked for photos of the screen, and I spoke with the business directly. That conversation confirmed it: this was a compromise, not a glitch.
What we cleaned up
We checked the computer and found signs of compromise. From there, we:
- cleaned up the computer
- cleaned up the email rules on the account
- sent an email to everyone affected
- gave the business advice on what needed to happen next, with a quote to secure the system properly
Why email rules matter
Email rules are a favourite of attackers once they’re inside a mailbox. A rule can forward copies of incoming mail to an outside address, or quietly move replies out of the inbox so the real user never sees a customer asking “did you really send this?”
That’s why cleaning up the computer isn’t enough on its own. A rule survives a restart and a clean-up of the computer, because it lives in the mailbox.
Microsoft’s guidance on responding to a compromised email account lists suspicious inbox rules among the common symptoms, including “rules that automatically forward email to unknown addresses” and rules that move messages into folders people rarely check.
Telling the people affected
Emailing everyone who received the fake messages is uncomfortable, and it’s the right thing to do. Customers who’ve been told can ignore or delete the emails. Customers who haven’t might click a link or pay an invoice.
The business’s customers had already done it a favour by ringing. The email closed the loop for everyone else.
Where they landed
The compromise was confirmed, the computer and mailbox were cleaned up, affected contacts were told, and the business had clear advice and a quote for the work needed to secure its systems.
If a customer ever rings about an email you didn’t send, don’t wait to see if it happens again. Ring your IT provider that day, and ask them to check the mailbox’s rules and forwarding as well as the computer.
If you’d like a second opinion on how your business would handle it, get in touch.
