Story one
The Friday invoice
A dental group with three offices and about 40 staff pays every vendor from one central mailbox. Late on a Friday, the accounts payable coordinator gets an email that looks like it is from the supplier all three offices use, saying an invoice is overdue. She clicks the link and signs in on what looks like the usual Microsoft page. It shows an error, so she tries the real site and heads home.
On Saturday, someone in another country tries to sign in to her mailbox with the password they collected. Her phone buzzes with a sign-in request she did not start. She taps Deny and calls the group’s IT provider, who resets the password and checks the account before Monday.
The attack reached step two and stopped there. Had it worked, the attacker would have been sitting inside the one mailbox that pays every vendor for every office.
Multi-factor authentication did not stop the email or the click. It made the stolen password useless. At 30 to 100 people, one mailbox can touch every vendor you pay, so tell your team: a sign-in request you did not start is an alarm, not a glitch.