What is a cloud-account compromise?¶
A cloud-account compromise occurs when somebody gains or uses access to a cloud account without proper authority.
That access may come through stolen credentials, a stolen session, malicious application consent, compromised recovery methods, delegated access or an attacker-controlled device.
What this means in practice¶
An attacker may use an existing session or access token. They may persuade the user to approve a multi-factor request. They may register a new trusted device, add a recovery method, create an administrator or grant an application long-term access.
Compromise may involve one brief login or continued access over weeks or months.
Start by preserving the relevant logs, account settings, sessions, devices, applications and administrator records. Build a timeline from the earliest suspicious event, not just the first event noticed.
Also identify what the attacker could reach. The account may provide access to files, email, other cloud services, recovery channels or organisational systems.
Where the compromise is active, security action may be urgent, but it must be coordinated with evidence preservation and specialist support.
What this may show¶
Signs can include unfamiliar sessions, new devices, changes to security settings, impossible-travel alerts, unusual sharing, new users, mailbox rules, deleted logs, unexpected applications or activity outside normal working patterns.
What this does not show on its own¶
The dangerous assumption is that compromise always means the password was stolen.
But unusual activity does not automatically prove compromise. Travel, VPN use, shared accounts, automation and legitimate administrator actions may produce similar records.
What to do next¶
Identify what access route was used and whether the attacker created persistence that could survive a password reset.
Key takeaway
Cloud compromise is unauthorised access through any valid or stolen route, so identify the initial entry, persistence, actions taken and records that preserve the timeline.