At 02:41 on a Tuesday, our SOC's identity analytics flagged an anomaly on a Geneva-based client tenant: a slow, distributed wave of failed sign-ins against thirty mailboxes, sourced from residential proxies across four continents. No single source tripped a lockout. Together, they formed the unmistakable signature of credential stuffing — testing username and password pairs leaked from unrelated breaches.
The timeline
- 02:41 — Detection: impossible-travel and password-spray heuristics correlate across the tenant; an incident is opened automatically.
- 02:43 — Containment: conditional-access policy tightens to require MFA for all sign-ins from unfamiliar networks; the attacking ASN ranges are blocked at the identity layer.
- 02:45 — One valid hit: a single account returns a successful first-factor authentication. The MFA challenge is not completed. The account's sessions are revoked and its password forced to reset.
- 03:10 — Hunt: retro-search over 30 days confirms no prior successful access from the campaign's infrastructure; the credential pair is traced to a 2024 third-party breach.
- Morning — Client debrief: one page, four actions, no data accessed.
What actually stopped it
Nothing here required exotic tooling. Three controls did the work: MFA on every account with no legacy-protocol exceptions; identity telemetry flowing into a SOC that watches it at 02:41 and not just at 09:00; and conditional access that can be tightened in minutes when the picture changes. The four-minute figure on our homepage is not marketing — it is the gap between detection and containment in incidents like this one.
The uncomfortable lesson
The tested password was valid. It had been reused on a third-party service that was breached a year earlier. Password hygiene programmes matter, but the honest conclusion is simpler: assume some credentials are already out there, and build the identity layer so that a valid password alone is never enough.
If you cannot say who watched your tenant at 02:41 last night, that is the gap our SOC-as-a-Service closes. Details have been altered to protect the client; the pattern, and the response, are exactly as described.
Draft article for the site mockup — technical review by the InterHyve team pending before publication.
Talk to our engineersLet's look at your environment.
A one-hour assessment with a senior engineer. No sales script, no obligation.