In September 2026, a Texas business engaged Ironfield Cyber to manage its IT and cloud security. The first minutes of onboarding turned a routine setup into an incident response. The client's identity is withheld.
The onboarding that became an incident response
When a new client comes on board, Ironfield connects to its Microsoft 365 environment and reviews sign-in activity, MFA configuration, mail flow and inbox rules, admin permissions, and other security indicators.
During this onboarding, monitoring flagged an unauthorized actor who had already established persistent access. They were not knocking on the door. They were already inside.
What the team found
- Forwarding rules were sending copies of a user's email to an outside address.
- An attacker-registered MFA method on a leader's account could allow re-entry after a password reset.
- Inbox rules marked security alerts as read and moved them to Deleted Items.
- Sign-ins came from foreign datacenter IP addresses that had not been flagged.
What Ironfield did
- Revoked active sessions and reset credentials on affected accounts.
- Removed the MFA methods the attacker had registered.
- Deleted malicious forwarding and inbox rules.
- Reviewed sign-in and mailbox audit logs to document the access timeline and give the client facts to assess its obligations.
- Hardened the environment with conditional access policies, single sign-on, and 24/7 monitoring.
Why this matters for construction and energy companies
A contractor's or energy company's inbox carries bids, pay applications, vendor invoices, change orders, and the banking details behind them. An attacker inside that inbox can read messages and send convincing payment instructions from a real company address.
Field operations raise the stakes. When email, scheduling, and project platforms go down, crews can stand idle while deadlines keep moving.
The question to ask about your own company
This client had an IT provider and MFA turned on. What it did not have was anyone watching what happened after someone signed in. If someone were inside your email right now, reading bids and payment traffic, would you know?