How might an investigator recognise unauthorised cloud access?¶
Unauthorised cloud access is usually recognised by a pattern of evidence rather than one decisive alert.
The investigation may begin with an unfamiliar login, unexpected file activity, a security warning, changed settings or the user reporting that something is wrong.
What this means in practice¶
Legitimate travel, mobile networks, VPNs, remote work and provider routing can all produce unusual records. Equally, sophisticated compromise may use familiar devices, sessions or locations and trigger no obvious alert.
What this may show¶
These may include a new device, unexpected authentication method, unfamiliar application consent, changes to recovery details, new forwarding rules, altered permissions, new administrators, large downloads, unusual sharing or activity at an unexpected time.
What this does not show on its own¶
The dangerous assumption is that one unusual IP address or location proves an attacker was present.
Do not rely only on the user’s memory. They may not recognise legitimate background activity, or they may be unaware that access has continued.
What to do next¶
Look for several indicators occurring together.
Check whether the activity relates to a fresh login, an existing session, a token, delegated access or an automated process.
Compare the event with the user’s normal pattern, known devices, work schedule, travel, approved applications and administrative activity.
Preserve provider logs, security alerts, session details, account changes, application permissions and relevant device evidence. Record the time zones used by each source.
Ask what happened before the suspicious event. A phishing message, password reset, multi-factor approval or new application may explain the access route.
Key takeaway
Recognise unauthorised access by combining login, session, device, application and account-change evidence, while testing legitimate explanations for each indicator.