
A Failed Credential Grabbing Attack, Stopped at the Endpoint
Who
Midwest Bar Accounting, a Detroit-based bar and restaurant accounting firm with two office locations and 35 employees. Roger Thornhill had been an accountant and franchisee consultant there for 14 years.
It is like Restaurant Impossible for accounting nerds. I help owners make smart, strategic financial decisions based on the hospitality industry best practices.
Roger Thornhill, Midwest Bar Accounting
What
Roger exchanges DocuSign documents daily with clients and prospects, including engagement letters, business associate agreements, and tax forms. Awaiting a signed engagement letter, he received an email asking him to log in to DocuSign. Though unusual, he thought nothing of it, moved too quickly, and clicked on a link in the email.
Do you ever have that sinking feeling that you know you are doing something and it does not feel quite right, and you do it anyway? I guess I was just working too fast.
Roger Thornhill
When
July 2023.
What Happened Next
A piece of keylogging malware attempted to install itself behind the scenes on Roger laptop. Dynamic Edge OS System Protection stopped it immediately and alerted Roger to the malicious attempt with a pop-up message.
As soon as I received the warning on my desktop, I knew I better call the Help Desk.
Roger Thornhill
An engineer took over immediately, isolating Roger machine from the rest of the network. They scanned his machine for malware, forced a password reset for all of his network credentials including DocuSign, and scanned the entire company network to confirm that no malware had traveled between devices.
The Outcome
Network scans did not identify any unauthorized downloads and Roger got back to work.
I am a little embarrassed that I fell for what now seems like a pretty obvious trick. However, I am relieved to know that our firm has invested in the solutions we need. Such a little mistake could have turned into a disaster.
Roger Thornhill
Why It Matters
DocuSign holds roughly 77.64% of e-signature market share according to Statista, which makes it an obvious brand for attackers to impersonate. Digital Information World counted some 30 million such attacks in 2022.
Security works best in intertwined layers. In this case, the phishing email got past the spam filter and the employee himself, but OS System Protection alerted him that something was wrong.
Kevin Wilson, Chief Information Security Officer, Dynamic Edge
