Varyence cases wave

The story

A US-based HealthTech AI startup had the right base security controls in place. Multi-factor authentication was enabled. Email authentication protocols were configured. Audit logging was active. By any standard checklist, the organization had covered the basics.

In May 2026, none of that stopped a sophisticated attacker from getting in.

Using a technique specifically designed to bypass standard MFA, the attacker stole a valid authenticated session from an employee. Not the password, the session itself. That distinction matters: the attacker was already inside, with no need to log in again and nothing left to trigger an alert.

What followed was deliberate and patient. The attacker monitored the employee's inbox, identified an active vendor billing thread, and crafted a fraudulent payment instruction designed to look like a routine internal forward. A hidden rule was created to suppress any vendor follow-up automatically. The employee would see nothing out of the ordinary.

The payment was processed four days later. The money went to a bank account the legitimate vendor had never seen.

The fraud surfaced eight days after that, not from any internal alert, but because the vendor called to say the funds hadn't arrived.

The startup engaged Varyence immediately. What the investigation uncovered and what was put in place to prevent it from happening again is what this case study is about.

Let's discuss your challenge

Schedule consultation

Project overview

Varyence conducted a full BEC incident investigation, containing the threat, rebuilding the attack timeline, deploying phishing-resistant access controls, and preparing the cybersecurity incident report for insurance claim submission.

Icon with a planet
Customer Location
USA
Icon of geographic destination
Team Location
Ukraine, EU & USA
Icon with team interaction
Team Size
6-8
Icon of clock
Project Length
May 2026 — Ongoing

Client challenge

The startup needed answers fast, and they needed them to be defensible for an insurance claim:

  • Was the attacker still inside the environment?
  • How did they bypass MFA?
  • Was any patient data accessed or exposed?
  • What happened, in what order, and with enough detail for an insurance submission?
  • How do we make sure this cannot happen again?

As a healthcare company, the HIPAA stakes were immediate. Any potential exposure of protected health information required a fast, accurate determination of whether breach notification obligations applied.

Nothing had flagged the attack. The MFA that failed was real, properly configured MFA, not a gap in setup. The fraudulent message came from a legitimate internal account. The attacker used the organization's own tools against it and left almost no trace doing so.

Our approach

We utilize industry best practices & leverage our global delivery capabilities to ensure successful business outcomes for our customers.

Solution delivered

Varyence conducted a full attack reconstruction of the environment, traced the breach from the first unauthorized access through to the fraudulent payment, and delivered a fully contained and documented incident response.

Attack reconstruction

Using sign-in and audit log data, Varyence rebuilt the complete attack timeline: how the attacker entered, how long they had access, what they did, and how they concealed their activity. The investigation confirmed the scope of exposure and provided the evidentiary record needed for the insurance claim.

WHAT HAPPENED ATTACK STAGE
Attacker stole a valid, authenticated session token using a phishing technique that bypassed standard MFA Initial Compromise
Stolen session reused over several weeks with no re-authentication required Persistent Access
Fraudulent vendor invoice instruction sent from the employee's own mailbox, with no trace left in Sent Items Execution
Hidden mailbox rule created to automatically suppress all vendor follow-up correspondence Concealment
Payment processed to an attacker-controlled bank account Financial Loss
Fraud identified 8 days later when the legitimate vendor reported non-receipt of funds Detection

Containment

Upon completing the investigation, Varyence executed full containment of the compromised account:

  • All active sessions revoked
  • Credentials reset
  • Authentication methods re-enrolled from scratch
  • Attacker's concealment rule removed

Post-containment review confirmed no further unauthorized access.

Phishing-resistant controls

To close the exact gap the attacker exploited, Varyence deployed a defense-in-depth authentication stack for key executive accounts:

  • FIDO2 passkey authentication, phishing-resistant by design, cannot be captured or replayed
  • Passkey-only sign-in enforced, with all weaker fallback methods removed
  • Sign-in restricted to organization-managed devices only
  • Geographic access restriction applied to permitted locations

The same attack cannot succeed against these controls. An attacker would need a physical hardware key, a corporate-managed device, and an approved location simultaneously.

Insurance claim support

Varyence prepared a full cybersecurity incident report for the startup's insurance provider, covering the complete attack narrative, evidence chain, data exposure scope, and all remediation actions taken. The report confirmed no PHI or PII was exposed and that no HIPAA breach notification obligation applied.

Technical components

Varyence handled the full scope of the engagement: incident investigation (sign-in logs, audit logs, mailbox forensics), attack reconstruction and attacker IP analysis, account containment and credential remediation, FIDO2 passkey deployment and Conditional Access hardening, HIPAA scope determination and data exposure analysis, cybersecurity incident report preparation for insurance submission, and bank notification and fraud recovery process support.

Solution impact

  • Breach contained: all attacker access revoked within 24 hours of detection; no continued unauthorized access observed
  • Zero data exposure: no patient data accessed or exfiltrated; no HIPAA breach notification obligation triggered
  • Phishing-resistant controls deployed: FIDO2 passkey, managed device requirement, and location restriction deployed for key executive accounts
  • Fraudulent transfer identified: fraudulent payment identified; bank notified and fund recovery process initiated
  • Evidence preserved: full forensic chain of custody documented and maintained for insurance review
  • Insurance claim supported: comprehensive cybersecurity incident report prepared and submitted to insurer

Why Varyence?

Varyence can help you drive growth, transform your business, and reduce risk.

You have many choices of who to trust with your budget, business reputation and business objectives and we take that responsibility very seriously.

Since we take this responsibility very seriously, we are selective regarding new clients with whom we engage. This helps us maintain high quality work for our customers.

As a trusted business technology partner for over 10 years to customers worldwide, below are some of the reasons they chose to place that trust in us.

Excellent ratings from clients
Passionate problem solvers
Global delivery capabilities
Best practice approach
Consistent results
Business savvy
Industry expertise
Technical know-how
Varyence appointment wave

Are you facing a business challenge? We are ready to help!

Varyence appointment wave