Case Studies

Attacks that worked — and how they get stopped.

These are composite stories built from the kinds of attacks we see across Arkansas schools and businesses. Names and details are changed; the techniques, and the lessons, are real.

Case 01 · K-12 district
$38K
walked out the door in gift cards — from one convincing email.
Phishing / BEC

The gift-card email from the "superintendent"

A district business manager got a message that looked like it came straight from the superintendent:

"Are you at your desk? I need you to grab some gift cards for a staff appreciation thing — keep it quiet, it's a surprise."

The display name was perfect. The reply-to address wasn't. Without training, that email gets paid — and it did.

How it gets stopped

Phishing-aware staff who check the real address, a culture of reporting, and email rules that flag look-alike senders — exactly what security awareness training and a basic email-security review put in place.

Case 02 · 12-person firm
4,000 mi
the distance a stolen login "traveled" in under an hour.
Account takeover

The login that traveled 4,000 miles

The office manager clicked a "Microsoft password expired" link and typed her credentials into a page that looked exactly right. Within the hour, someone logged in from overseas, quietly set up a mailbox rule to hide their tracks, and started reading invoices to plan a wire-fraud scam.

How it gets stopped

ITDR flags the impossible-travel login and the rogue inbox rule in real time, isolates the account, and kills the session before a dollar moves — the kind of thing a once-a-year test would never catch.

Case 03 · Manufacturer
1
forgotten remote-access service — the only door an attacker needs.
Exposed service

The open door nobody tested

A manufacturer assumed their firewall had them covered. An external penetration test found a forgotten remote-access service exposed to the internet with a weak password — the same foothold ransomware crews scan for every single day.

How it gets stopped

We found it first. They closed it in an afternoon, and a retest confirmed the door was shut. No breach, no headline, no ransom — just a gap caught before anyone else found it.

What would an attacker find on your network?

There's only one way to know for sure — and it's a lot cheaper than finding out the other way. Start with a free assessment.

Start with a free assessment