Phishing incident: the questions I would have asked if I had worked on it

Phishing incident: the questions we would have asked if we had worked on it
Phishing incident: the questions I would have asked if I had worked on it
Summary

When a phishing incident occurs, most organizations focus on containment: passwords are reset, multi-factor authentication is enabled, suspicious emails are removed, customers are notified, and, as soon as possible, operations return to normal. These are important steps. However, they answer only one question: “How do we stop the immediate threat?”

An investigation asks different questions. It seeks to understand how the incident occurred, what exposure exists, whether risks remain, and what lessons can be learned.

Following the phishing incident discussed in the previous case study, I was not asked to perform an investigation as the company wanted to internally resolve the incident and move on. However, as an investigator, there are ten questions I would have wanted answered before declaring the matter fully understood. 

Importantly, these questions are not intended to support a particular theory. Their purpose is to identify, test, and eliminate possible explanations.

The previous articles prompted by this case

If you missed the series on the phishing incident, here are the links to catch up: 

Question 1: how did the attacker obtain the recipient list?

One of the first questions I would ask is deceptively simple. How were recipients selected?

The phishing campaign reached:

This suggests the attacker had access to information about business relationships.

Possible explanations could include:

Understanding how recipients were selected can significantly narrow the list of possible attack paths.

Question 2: was a business account actually compromised?

Many phishing incidents begin with assumptions. If a phishing email appears to originate from a company, people often assume that a company account was compromised. That assumption may be correct. It may also be wrong. An investigator would seek evidence.

Questions might include:

Until evidence exists, compromise should remain a hypothesis rather than a conclusion.

Question 3: what was the earliest known indicator of activity?

Organizations often begin investigating at the moment an incident is reported. Attackers typically begin much earlier. An investigator would attempt to establish a timeline.

Examples include:

The earlier the timeline begins, the clearer the picture becomes.

Question 4: did historical credential exposure contribute to the incident?

During independent analysis, I identified historical breach records associated with one of the accounts involved. This finding does not prove relevance. However, it creates an investigative lead.

Questions worth exploring include:

Credential exposure often plays a larger role in incidents than organizations initially realize.

Question 5: was the personal use of business identities a contributing factor?

One observation from publicly available data was the appearance of a business email address within datasets associated with consumer-oriented services unrelated to the company’s industry. 

Again, this proves nothing on its own. However, it raises important questions. If business identities are used across a wide range of services:

The broader the digital footprint, the larger the potential attack surface.

Question 6: what reconnaissance did the attacker perform?

Most successful phishing attacks begin with research. Investigators should ask:

Understanding what the attacker could see often reveals why specific targets were chosen. It also helps organizations understand their own exposure.

Question 7: where identity elements being reused elsewhere?

During OSINT analysis, various usernames, profile references, and identity-related artefacts appeared across multiple platforms. Some appeared legitimate. Others raised questions regarding impersonation, duplication, or abandoned accounts.

An investigator would want to determine:

Identity exposure is often overlooked during technical investigations despite its value to threat actors.

Question 8: where vendors and customers also victims?

One of the most significant aspects of this case was that the phishing campaign extended beyond internal employees. This changes the nature of the incident.

The investigation should examine:

Modern phishing campaigns frequently target trust networks rather than individual organizations. The blast radius may be considerably larger than initially believed.

Question 9: what evidence supports the conclusion that the incident was resolved?

This may be the most important question in the entire investigation. Organizations often communicate that an issue has been resolved. An investigator wants to understand why. What evidence supports that conclusion?

Examples might include:

Confidence should be based on evidence rather than assumptions. The stronger the evidence, the stronger the conclusion.

Question 10: what risks remain today?

Many investigations focus exclusively on historical events. A better approach is also asking what remains unresolved.

Questions may include:

A completed investigation should improve future security, not simply explain past events.

The value of questions

Many people assume that investigators are primarily in the business of finding answers. In reality, investigators spend much of their time asking questions. 

Good questions eliminate assumptions. Good questions challenge conclusions. Good questions reveal gaps in understanding. In cybersecurity, the first explanation is not always the correct explanation. The most obvious explanation is not always the most complete explanation.

The purpose of an investigation is not to prove a preferred theory. It is to follow evidence wherever it leads.

Why this matters

The phishing incident that inspired this series may ultimately have a simple explanation. Or it may involve multiple contributing factors. Without access to evidence, there is no responsible way to know.

What this case demonstrates, however, is that incidents often reveal much broader issues than initially expected. Historical breach exposure. Identity managementDigital footprint analysis. Third-party risk. Business process weaknesses. Trust relationships.

These factors rarely appear in the first incident report. Yet they often become the most valuable findings.

Final thoughts

Every phishing incident creates two opportunities. The first is to contain the immediate threat. The second is to learn something meaningful about organizational risk.

Many organizations complete the first task successfully. Fewer invest the time necessary to achieve the second.

The difference often determines whether an incident becomes an isolated event or the beginning of a stronger security programme.

The most valuable findings are often not contained within compromised systems. They exist in the relationships, exposures, identities, and assumptions that surround them. Negative PID helps organizations investigate incidents, analyse digital exposure, perform OSINT assessments, and identify risks that may remain hidden long after technical remediation is complete.

Learn more at Negative PID.

Share this post :