24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Services & Consulting · 2026
Services & Consulting · Case 2026

O365 mailbox takeover + auto-forward · 11-month supplier BEC · 2.6M TL loss detected

The O365 mailbox of an accounting assistant at a services firm was compromised via phishing 11 months earlier. The attacker used an "Inbox rule" to forward all supplier invoices to themselves, changed the IBAN and sent fake invoices. DSET detected 11 months of losses, the insurance reimbursement of 58% was approved, and the KVKK penalty risk was avoided.

Duration
11-month detection · 3 months of hardening
Scope
38 affected suppliers · 2.6M TL total · 280 fake invoices
Customer Satisfaction
★★★★★

01 The Challenge

A supplier called: "our money has not arrived for 11 months." Microsoft Defender had raised an "anomalous forwarding rule" alert 11 months earlier that had not been closed. Audit log: login from a Nigeria Lagos IP, which the assistant saw as "normal mail." The attacker had sent 280 fake invoices, with IBANs going to 4 mule accounts (Romania, Latvia, Turkey). A total of 2,640,000 TL in payments went to fake accounts.

02 DSET's Approach

01

T+0 · Containment

Entire O365 tenant: MFA enforced + Conditional Access + all forwarding rules revoked. The attacker was kicked out of all accounts within 24 hours.

02

T+24h · Microsoft DART

Joint work with the Microsoft Detection and Response Team, a 4-day investigation. All IOCs of the attacker from 11 months earlier were revealed.

03

T+72h · DSET forensic investigation

Mail header analysis: 280 fake invoices, 4 mule accounts. Initial access: a fake "Microsoft password expired" form (a phishing kit from Lagos).

04

T+1 week · KVKK 72 hours

A breach notification was filed, no penalty. A cyber insurance policy claim file was opened, with transparent notification to suppliers.

05

T+30 days · Supplier approval system

DSET set up a "phone + written verification for IBAN changes" procedure. 38 suppliers were aligned with the new process.

06

T+60 days · ZTNA + DLP

O365 ZTNA + DLP policies active. All accounting accounts secured with FIDO2 hardware keys (YubiKey). DSET quarterly phishing simulation.

07

T+6 months · Insurance reimbursement

Cyber insurance reimbursement of 1.5M TL (total 58%). Supplier trust was preserved thanks to transparency; no contracts were cancelled.

03 Results in Numbers

2.6M TL
11-month loss detected
58%
Insurance reimbursement
0
KVKK penalty
0
Supplier loss
0
New attacks (12 months)
96%
Employee awareness

04 Customer Testimonial

"

They detected 11 months of losses within 1 week. Thanks to our notification within the KVKK 72-hour window we received an insurance reimbursement instead of a penalty. Our suppliers still work with us.

General Manager
Services & Consulting · Ankara
★★★★★

05 Key Takeaways

O365 "forwarding rule" alerts must not be ignored; always investigate them
MFA + Conditional Access is not enough for a single account; it is mandatory for the entire tenant
If the KVKK 72-hour breach notification is filed proactively, the penalty risk drops by 95%
FIDO2 hardware keys (YubiKey) are indispensable for accounting + finance

06 Services Used in This Case

Digital Forensics

Trust in evidence is trust in justice.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms