The challenge
A Geneva-based international organisation with staff across multiple field offices relied on Microsoft 365 for email and collaboration. Like every organisation of its kind, its people reused passwords across services — and some of those services had been breached elsewhere. That made it a textbook target for credential stuffing: automated login attempts using username and password pairs leaked from unrelated breaches, distributed across residential proxies to stay under lockout thresholds.
What we did
The client's tenant was under InterHyve's managed SOC. Identity telemetry flowed continuously into our monitoring — and at 02:41 on a Tuesday, our analytics correlated a slow wave of failed sign-ins across thirty mailboxes, sourced from four continents. No single source tripped an alert on its own; together, they formed the unmistakable signature of credential stuffing.
Within two minutes, conditional-access policy was tightened to force MFA on every unfamiliar sign-in, and the attacking network ranges were blocked at the identity layer. One account returned a valid first-factor authentication — but the MFA challenge was never completed. That account's sessions were revoked and its password forced to reset. A thirty-day retro-hunt confirmed no prior successful access from the campaign's infrastructure.
The outcome
No data was accessed. No account was compromised. By the morning the client had a one-page debrief with four concrete actions. The single valid credential pair — reused from a third-party breach a year earlier — was reset before it could be used. The whole event, from detection to containment, spanned four minutes.
What made the difference
Three controls did the work, none of them exotic: MFA on every account with no legacy-protocol exceptions; identity telemetry flowing into a SOC that watches it at 02:41 and not just at 09:00; and conditional access that can be tightened in minutes when the picture changes. The four-minute figure isn't marketing — it's the gap between detection and containment when someone is actually watching.
If you cannot say who watched your tenant at 02:41 last night, that is the gap our SOC-as-a-Service closes.
Details have been altered to protect the client; the pattern and the response are exactly as described.
Have our SOC watch your tenantLet's look at your environment.
A one-hour assessment with a senior engineer. No sales script, no obligation.