thecomputerguy
Well-Known Member
- Reaction score
- 1,414
My client is the lawyer for an national insurance company. They were supposed to receive $300k from a small construction company. The lawsuit alleges that the insurance company never received the money and can prove that they never received the money. The construction company alleges the money was sent in three $100k payments.
My client (the lawyer) contacted me to take a look at the email correspondence and it appears that illegitimate domains were registered on both ends to make this happen.... think the company was contosollp.com and contosoillp.com was registered.
I was tasked, essentially to take a look at where the compromise may have occurred. The illegitimate domains have already been decommissioned and the money is gone. The national insurance company appears to be using ProofPoint as a spam filter. I'm not sure how to look beyond that to see who their host actually is but I'd put money on it being M365.
The construction company has a CNAME record pointing to mail.contoso.com - when visiting mail.contoso.com I get redirection to a mail service called SmarterMail. Upon further investigating it appears SmartMail is a pop/imap only email service maybe linux based?
www.smartertools.com
The further complicate things, the owner of the construction company was using a Hotmail account and was CC'd on all these emails a lot of which were using the illegitimate domain.
I explained in an email to my client (the lawyer) that without being able to get hands on either domain it would be impossible to determine with absolute certainty where the compromise occurred but in my opinion it is likely that the compromise occurred on the construction companies end due to not adopting a true business class email solution like M365 or Google Apps, additionally using a Hotmail account in all of this further complicates the matter as it also does not, in my opinion fulfill the requirements for an acceptable business class email solution.
THEIR lawyer, basically send a letter saying that for us to call "SmarterMail" and "Hotmail" inadequate and less superior than a M365 email service is completely incorrect as Hotmail is a "Cloud-Based Microsoft Server"
Any suggestions on further investigating this?
My client (the lawyer) contacted me to take a look at the email correspondence and it appears that illegitimate domains were registered on both ends to make this happen.... think the company was contosollp.com and contosoillp.com was registered.
I was tasked, essentially to take a look at where the compromise may have occurred. The illegitimate domains have already been decommissioned and the money is gone. The national insurance company appears to be using ProofPoint as a spam filter. I'm not sure how to look beyond that to see who their host actually is but I'd put money on it being M365.
The construction company has a CNAME record pointing to mail.contoso.com - when visiting mail.contoso.com I get redirection to a mail service called SmarterMail. Upon further investigating it appears SmartMail is a pop/imap only email service maybe linux based?
SmarterTools Incorporated
Our business email server, team chat, online help desk and web analytics software will help your business succeed. For business or personal users worldwide.
The further complicate things, the owner of the construction company was using a Hotmail account and was CC'd on all these emails a lot of which were using the illegitimate domain.
I explained in an email to my client (the lawyer) that without being able to get hands on either domain it would be impossible to determine with absolute certainty where the compromise occurred but in my opinion it is likely that the compromise occurred on the construction companies end due to not adopting a true business class email solution like M365 or Google Apps, additionally using a Hotmail account in all of this further complicates the matter as it also does not, in my opinion fulfill the requirements for an acceptable business class email solution.
THEIR lawyer, basically send a letter saying that for us to call "SmarterMail" and "Hotmail" inadequate and less superior than a M365 email service is completely incorrect as Hotmail is a "Cloud-Based Microsoft Server"
Any suggestions on further investigating this?