What signs may indicate cloud-account compromise?¶
Cloud-account compromise may be indicated by unusual sessions, new devices, unfamiliar applications, recovery changes, forwarding rules or activity inconsistent with the user’s normal role.
Evidential caution: that compromise always produces a foreign login or obvious security alert.
What this means¶
An attacker may use the victim’s device, stolen session token, familiar application or nearby network.
One unusual login may be legitimate. Several related changes may show takeover or persistence.
Review the underlying authentication, session, audit and application records.
Consider the user’s travel, work pattern, approved software and recent organisational changes.
A compromise may also be partial. An attacker may access one application or shared resource without taking full control of the account.
A useful compromise assessment compares expected activity with actual activity over time. A single event may be ambiguous, while the sequence can reveal the point at which control changed.
Where the provider shows a risk score or impossible-travel alert, preserve the rule and underlying events. The risk label is useful context, but the investigative value comes from the activity that triggered it.
What to check or do next¶
- Look for new or unexpected sessions, token use, administrator roles, consented applications, trusted devices and recovery methods.
- Check for password resets, multi-factor changes, mailbox rules, file-sharing changes, mass downloads, deleted alerts and logging changes.
- Compare the timing and sequence of events.
- Do not rely only on provider risk labels.
- Where possible, compare the cloud records with device artefacts, help-desk reports, security alerts and communications.
Operational takeaway
Identify compromise through the pattern of sessions, tokens, applications, recovery changes and account behaviour, not through one unusual login or alert alone.