What signs may indicate cloud-account compromise?¶
Compromise is usually indicated by a connected pattern of unexpected access, changes in account control or persistence - not one foreign-looking login. The strongest assessment compares the account's expected operation with the full event sequence.
Look across access and configuration¶
Relevant indicators include new sessions or devices, unusual token use, unfamiliar applications, administrator or recovery changes, new trusted devices, mailbox or sharing rules, mass or selective downloads, deleted alerts and reduced logging.
Review underlying authentication, session, token, application and audit events. Preserve the rule and input events behind any risk score or “impossible travel” alert; the provider label is context, not proof.
Test legitimate and partial explanations¶
Travel, approved software, organisational change and a user's work pattern can explain individual anomalies. An attacker may also use the victim's device, an existing session, a familiar application or nearby network, leaving no obvious login anomaly.
Compromise can be partial: one application, shared resource or delegated permission may be affected without complete account takeover. Identify the point at which behaviour or authority changed, and compare cloud events with device artefacts, help-desk records, communications and security data.
State which combination supports compromise and which benign alternatives remain, rather than treating an unusual event as self-proving.
The point to remember
Assess compromise from the sequence of sessions, tokens, applications and control changes, testing both subtle access and legitimate explanations.