The Attack That Doesn't Look Like an Attack: Account Takeover and Why We Added ITDR

Account takeover is now one of the costliest ways a business loses money to cybercrime — and it sails past both your email filter and your MFA. Here's how the attack works, why your existing tools miss it, and the identity layer (ITDR) we added to close the gap.



KEY TAKEAWAYS
  • Account takeover — not ransomware — is one of the most likely ways a small business loses money to cybercrime
  • These attacks come from a hacked colleague’s real account, and routinely slip past both email filters and MFA
  • ITDR watches the identity after login and contains a compromise automatically — the gap MFA and email security leave open
  • We added an ITDR layer to our stack; we like Petra, Huntress, and Blumira and match the right one to your environment — ask us

The attack that doesn’t look like an attack

For years, the advice was simple: don’t click suspicious links, and don’t trust the email from the “Nigerian prince.” That advice is now out of date.

Today’s most successful attacks don’t come from a stranger. They come from a trusted colleague whose account has already been hacked. The attacker uses that real account to send a real-looking message — a shared document, an invoice, a quick request — and because it comes from inside a domain you trust, it slides right past spam filters and email security. Your team is far more likely to click, because everything about it looks legitimate.

The numbers are not subtle:

  • More than 90% of cyberattacks start with a phishing email. (CISA)
  • Between 2013 and 2023, business email compromise (BEC) drove more than $55 billion in global exposed losses — that figure counts attempted and intercepted dollars as well as actual theft. (FBI IC3)
  • In 2023, the average reported BEC loss was about $137,000; the median was closer to $50,000, because a handful of very large incidents pull the average up. (FBI IC3 / Verizon DBIR)
  • An organization with fewer than 1,000 employees has roughly a 70% chance of seeing at least one BEC attempt in any given week. (Abnormal Security, 2024)

BEC has been one of the two costliest categories of cybercrime the FBI tracks for years — it was the single largest category by reported losses in 2020 and 2021, and today it ranks second only to investment fraud. And this stopped being an enterprise-only problem a while ago. Attackers automate, so company size doesn’t protect you — as the weekly-attempt number above shows, small businesses are squarely in scope.

Why your existing tools miss it

Two assumptions trip most businesses up.

“Our email security catches phishing.” Modern attacks arrive from a hacked-but-legitimate account, often carrying a Microsoft-laundered link to a shared file or an invoice request. There’s nothing for a filter to flag. The sender is real. The link points to real Microsoft infrastructure. It gets through.

“We have MFA, so we’re covered.” MFA is necessary, but it’s no longer sufficient. Microsoft observed a 146% jump in adversary-in-the-middle (AiTM) phishing — the kind purpose-built to defeat MFA — in 2024. In one security firm’s incident-response caseload, nearly 80% of BEC victims had MFA correctly enabled. The reason usually isn’t that someone typed their code into a fake page (though that happens). It’s that modern phishing kits proxy the real login and steal the session token after MFA has already succeeded — then ride that valid, already-trusted session. To Microsoft 365, nothing looks wrong. On top of that, attackers increasingly log in from U.S. residential IP addresses specifically so they don’t look “foreign” to a simple location check.

And once they’re in, they move fast — these attacks are heavily automated. The attacker goes straight for the crown jewels — invoices, financial statements, payroll, legal documents — reads and exfiltrates what matters, sets up hidden inbox rules, and starts sending fraud from your domain. Every minute counts, and the damage breaks down into three buckets:

RiskWhat actually happens
FinancialFraudulent invoices to your clients, tampered banking details, diverted payroll. Average reported BEC loss: about $137,000.
DataSensitive emails and files — invoices, financials, passwords, legal documents — accessed, exfiltrated, and often sold on the dark web or reused in the next attack.
ReputationalPhishing sent from your domain to your clients. If a client loses money, you may be on the hook legally or contractually.

This is the gap we wanted to close, and it’s specifically a Microsoft 365 identity problem — not something one more email filter solves.

What we did about it: we added an ITDR layer

We added ITDR — Identity Threat Detection and Response — to our managed security stack. ITDR is a different job than antivirus or email filtering. Antivirus watches the device. Email security watches the inbox. ITDR watches the identity — the account itself and everything it does across Microsoft 365: Entra ID sign-ins, Exchange, SharePoint, OneDrive, and Teams. It’s built for exactly the attack described above: the one that already got past the filter and past MFA, and is now logged in and looking around.

A good ITDR layer does three things native Microsoft 365 doesn’t do well on its own:

  • It catches compromises in minutes, not days — by watching what an account does after login (mail rules, file access, app grants), not just where it logged in from. That’s how it flags the residential-IP, post-MFA, valid-session attack that location rules wave through.
  • It responds automatically. When a compromise is confirmed, the account is locked, sessions are killed, and the things attackers leave behind get cleaned up too — malicious inbox rules, rogue OAuth apps, attacker-added MFA methods. For a business without a 24/7 security team, automatic containment is the part that actually changes the outcome.
  • It doesn’t lock out your traveling employees. The good tools use behavioral analytics rather than a blunt “unusual location” rule, so your CFO logging in from a hotel doesn’t get locked out — but the attacker on a residential IP still does.

We don’t lock clients into one ITDR product — we’re candid about that. There are three we like most, and the right fit depends on what you already run: Petra (a surgical, MSP-first Microsoft 365 identity tool with the fastest automated remediation and two-click deployment), Huntress (managed ITDR backed by a 24/7 SOC, with humans in the loop), and Blumira (a SIEM-style approach with visibility well beyond Microsoft 365, strong for compliance reporting). We dig into how they compare in our Petra ITDR review and ITDR comparison. The point isn’t the logo on the dashboard — it’s that you have some ITDR coverage, and that it fits your stack, your compliance needs, and your budget.

Why this matters for our regulated clients

If you operate under HIPAA, CSBS, or another compliance regime, an account compromise isn’t just a cost — it’s a reportable event, and the documentation burden afterward is real. Fast detection shrinks the blast radius, and the forensic record a good ITDR tool produces — a clear, timestamped account of what the attacker touched, plus an executive-friendly report — is exactly the kind of evidence an examiner or an incident-response process wants to see. For our vCISO engagements, that combination is the point.

How to find out if you’re already exposed

Here’s the uncomfortable thing about account compromise: most businesses don’t know they have one. Attackers can sit quietly in a mailbox for weeks or months, reading and waiting for the right invoice to tamper with.

So rather than ask you to take our word for it, we’d rather show you. We can run a free scan of your Microsoft 365 environment. It works with your existing licensing, takes minutes to set up, and looks back through your logs to answer one question: is anyone already in here that you don’t know about? If the answer is no, you get a clean report and some peace of mind. If the answer is yes, you’ll be very glad you asked.


90%+
of cyberattacks start with a phishing email (CISA)
$55B+
global BEC exposed losses, 2013–2023 (FBI IC3)
146%
rise in MFA-bypass (AiTM) phishing in 2024 (Microsoft)
70%
weekly BEC-attempt odds for orgs under 1,000 staff (Abnormal, 2024)

Brivy tip

Run a free identity scan before anything else. It’s the fastest, lowest-risk way to find out whether someone is already in your Microsoft 365 tenant. We’re happy to run one with you and walk through the results — no commitment.


Account takeover & ITDR FAQs

What is ITDR?
ITDR stands for Identity Threat Detection and Response. It monitors your user accounts and identity activity — sign-ins, mailbox actions, file access, app grants — to detect and stop account takeovers, then automatically responds by locking the account, revoking sessions, and removing the attacker's persistence. It's distinct from antivirus (which watches devices) and email security (which watches inbound mail).
How is this different from the MFA and email filtering we already have?
MFA and email filters stop a lot of attacks, but today's most damaging ones are designed to get past both — modern kits steal a valid session token after MFA has already succeeded. ITDR is the layer that catches the attacker after they're already logged in, which is precisely where the other tools stop looking.
Do we need a specific Microsoft 365 license?
No. The ITDR tools we deploy work with Microsoft 365 Business Basic and above. If your license includes richer data, they use that too, but there's no Entra ID P1/P2 requirement.
Which ITDR tool do you use?
We don't lock clients into one tool, and we'll tell you that honestly. We like Petra, Huntress, and Blumira and match the right one to your environment — Petra for fast, surgical M365 identity containment; Huntress when you want a managed 24/7 SOC; Blumira for broader, compliance-oriented visibility. See our ITDR comparison for the details, or just ask us.
Can you check whether we're already compromised?
Yes — that's the free scan. It reviews your existing Microsoft 365 logs and tells you whether there's an active or past compromise you didn't know about. It works with your current licensing and takes minutes to set up.

Strengthen your identity security

Brivy IT assesses your Microsoft 365 identity posture and deploys the right ITDR layer for your business.

Cybersecurity →Managed IT →Get a Quote →


Worried about account takeover on your Microsoft 365?

We'll run a free identity threat scan and recommend the right ITDR fit — Petra, Huntress, Blumira, or a combination.

Request a Free M365 Scan

author avatar
John Huston
Skip to content
We improve our products and advertising by using Microsoft Clarity, Google Analytics, and other tools to understand how you use our website. By using our site, you agree that we and our partners may collect and use this data. Our privacy policy has more details.