BEC Exploited the One Gap Standard MFA Can't Close
How Varyence helped a US HealthTech startup contain a Microsoft 365 BEC attack, recover a fraudulent payment, and deploy phishing-resistant controls with zero PHI exposure.
How Varyence helped a US HealthTech startup contain a Microsoft 365 BEC attack, recover a fraudulent payment, and deploy phishing-resistant controls with zero PHI exposure.
A US-based HealthTech AI startup had the right base security controls in place. Multi-factor authentication was enabled. Email authentication protocols were configured. Audit logging was active. By any standard checklist, the organization had covered the basics.
In May 2026, none of that stopped a sophisticated attacker from getting in.
Using a technique specifically designed to bypass standard MFA, the attacker stole a valid authenticated session from an employee. Not the password, the session itself. That distinction matters: the attacker was already inside, with no need to log in again and nothing left to trigger an alert.
What followed was deliberate and patient. The attacker monitored the employee's inbox, identified an active vendor billing thread, and crafted a fraudulent payment instruction designed to look like a routine internal forward. A hidden rule was created to suppress any vendor follow-up automatically. The employee would see nothing out of the ordinary.
The payment was processed four days later. The money went to a bank account the legitimate vendor had never seen.
The fraud surfaced eight days after that, not from any internal alert, but because the vendor called to say the funds hadn't arrived.
The startup engaged Varyence immediately. What the investigation uncovered and what was put in place to prevent it from happening again is what this case study is about.
Varyence conducted a full BEC incident investigation, containing the threat, rebuilding the attack timeline, deploying phishing-resistant access controls, and preparing the cybersecurity incident report for insurance claim submission.
The startup needed answers fast, and they needed them to be defensible for an insurance claim:
As a healthcare company, the HIPAA stakes were immediate. Any potential exposure of protected health information required a fast, accurate determination of whether breach notification obligations applied.
Nothing had flagged the attack. The MFA that failed was real, properly configured MFA, not a gap in setup. The fraudulent message came from a legitimate internal account. The attacker used the organization's own tools against it and left almost no trace doing so.
We utilize industry best practices & leverage our global delivery capabilities to ensure successful business outcomes for our customers.
Varyence conducted a full attack reconstruction of the environment, traced the breach from the first unauthorized access through to the fraudulent payment, and delivered a fully contained and documented incident response.
Attack reconstruction
Using sign-in and audit log data, Varyence rebuilt the complete attack timeline: how the attacker entered, how long they had access, what they did, and how they concealed their activity. The investigation confirmed the scope of exposure and provided the evidentiary record needed for the insurance claim.
| WHAT HAPPENED | ATTACK STAGE |
|---|---|
| Attacker stole a valid, authenticated session token using a phishing technique that bypassed standard MFA | Initial Compromise |
| Stolen session reused over several weeks with no re-authentication required | Persistent Access |
| Fraudulent vendor invoice instruction sent from the employee's own mailbox, with no trace left in Sent Items | Execution |
| Hidden mailbox rule created to automatically suppress all vendor follow-up correspondence | Concealment |
| Payment processed to an attacker-controlled bank account | Financial Loss |
| Fraud identified 8 days later when the legitimate vendor reported non-receipt of funds | Detection |
Containment
Upon completing the investigation, Varyence executed full containment of the compromised account:
Post-containment review confirmed no further unauthorized access.
Phishing-resistant controls
To close the exact gap the attacker exploited, Varyence deployed a defense-in-depth authentication stack for key executive accounts:
The same attack cannot succeed against these controls. An attacker would need a physical hardware key, a corporate-managed device, and an approved location simultaneously.
Insurance claim support
Varyence prepared a full cybersecurity incident report for the startup's insurance provider, covering the complete attack narrative, evidence chain, data exposure scope, and all remediation actions taken. The report confirmed no PHI or PII was exposed and that no HIPAA breach notification obligation applied.
Varyence handled the full scope of the engagement: incident investigation (sign-in logs, audit logs, mailbox forensics), attack reconstruction and attacker IP analysis, account containment and credential remediation, FIDO2 passkey deployment and Conditional Access hardening, HIPAA scope determination and data exposure analysis, cybersecurity incident report preparation for insurance submission, and bank notification and fraud recovery process support.
Varyence can help you drive growth, transform your business, and reduce risk.
You have many choices of who to trust with your budget, business reputation and business objectives and we take that responsibility very seriously.
Since we take this responsibility very seriously, we are selective regarding new clients with whom we engage. This helps us maintain high quality work for our customers.
As a trusted business technology partner for over 10 years to customers worldwide, below are some of the reasons they chose to place that trust in us.