What is a cloud-account compromise?¶
A cloud-account compromise is unauthorised control or use of an account route. It is best treated as a testable sequence: authority was obtained, maintained and used for particular actions - not as a synonym for any unusual login or for “the password was stolen”.
Reconstruct acquisition, persistence and action¶
At 09:12 an unfamiliar application is granted access to Dave's Northstar account. At 09:18 it obtains token authority, at 09:26 it reads files, and at 09:31 a new forwarding rule appears. Dave reports that he intended only to open a document preview.
Test the proposition, including innocent explanations¶
Identify the first suspicious action and work backwards through sign-in, factor, recovery, device, consent, delegation and session records. Then follow downloads, sharing, deletion, forwarding, credential changes and other persistence.
Travel, new software, VPN use and legitimate administration can produce unfamiliar events. Conversely, a familiar device or network does not exclude stolen session use. The strength comes from the joined sequence, user account, device evidence, communications and provider alerts - not from one anomaly.
Containment may be urgent, but password resets, revocation and disabling applications change the environment. Preserve the accessible pre-change state where circumstances allow and record each protective action.
The point to remember
Describe compromise through the authority obtained, how it persisted and what it was used to do. Keep proof of unauthorised use separate from identification of the intruder.