
Case study Manufacturing
Active Exfiltration Surfaced in Employee Email
Unit6 observed multiple employee email accounts compromised and active data exfiltration from those accounts. Data movement was confirmed, but its contents and any containment remain unknown.
Impact summary
Unit6 observed multiple employee email accounts compromised and active data exfiltration from those accounts. Data movement was confirmed, but its contents and any containment remain unknown.

01 / Observation
What Unit6 saw
Unit6 telemetry showed:
- 01
Multiple employee accounts under attacker control
- 02
Active data exfiltration from those accounts
- 03
A similar access pattern associated with an access-broker ecosystem
02 / Significance
Why it mattered
A compromised mailbox can expose more than one inbox: conversations, contacts, and trusted communication chains can all become useful to an attacker.
This had progressed beyond access to active exfiltration, while the precise data set remained unknown.
03 / Confidence
How Unit6 established confidence
Confirmed account compromise and ongoing data exfiltration
The relationship among the observed actors remains unclear.
04 / Recommended response
What the customer could do
The observed data flow called for immediate action:
- Revoke affected sessions and credentials, then secure recovery channels
- Preserve mail and sign-in logs to establish the data scope
- Monitor for follow-on phishing or account use through trusted conversations
05 / Outcome not confirmed
Outcome
Data exfiltration was already active at the time of the report; the content and final volume are not documented.
Whether the organization contained the accounts or recovered the data remains unknown.



