{"id":316,"date":"2026-09-09T01:46:13","date_gmt":"2026-09-09T01:46:13","guid":{"rendered":"https:\/\/rjsecure.com\/?p=316"},"modified":"2026-09-09T01:48:27","modified_gmt":"2026-09-09T01:48:27","slug":"mfa-never-saw-the-phishing-smtp-did","status":"publish","type":"post","link":"https:\/\/rjsecure.com\/?p=316","title":{"rendered":"MFA Never Saw the Phishing. SMTP Did."},"content":{"rendered":"\n<p>Your mailbox can be abused without anyone opening webmail. Most people treat <strong>a hacked email<\/strong> as: someone logged into Gmail in a browser. A lot of real incidents are quieter. Someone gets a SMTP password, sends mail as you, and never touches the inbox. SMTP is how servers and apps send mail: WordPress, a monitoring box, a printer, an old phone. If that secret works, the provider will accept mail from any IP on earth. Multi-factor on the website does not pop up on port 587.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What it looks like<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Admin logs show SMTP and or outbound authentication traffic from impossible countries, i.e. logging in from a China IP but you are based in the US. <\/li>\n\n\n\n<li>A traffic spike of outgoing mail to people you do not know<\/li>\n\n\n\n<li>A \u201cnew login activity\u201d mail that says unknown login and an IP, with a subject so bland it dies in Notifications<\/li>\n\n\n\n<li>No new inbox rules, no forwarding, no web sessions<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>If recipients are random, the attacker brought their own list. They did not need your contacts. They needed your From: to look legitimate.<\/p>\n\n\n\n<p>If recipients are known, then the attacker spammed your entire global address list to try to get further credentials for compromise. <\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prevent it<\/h2>\n\n\n\n<p>1. Passwords &#8211;> long, unique, in a password manager. Eight characters is not enough, it should be minimum of 15 characters<\/p>\n\n\n\n<p>2. MFA &#8211;> Turn it on and leave it on. MFA prevents the user compromise. It does not approve each SMTP message.<\/p>\n\n\n\n<p>3. App passwords have full rights<br>One \u201capp password\u201d is not \u201calerts only.\u201d It can send or receive to anyone the account is allowed to mail. Best practices on app passwords email identity:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name them (server-alerts, iPad-mail, etc.)<\/li>\n\n\n\n<li>One per device<\/li>\n\n\n\n<li>Delete anything you do not recognize<\/li>\n\n\n\n<li>After an incident, revoke all of them and issue new ones<\/li>\n\n\n\n<li>Practice password rotation to prevent any potential collision attacks or compromised credentials<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>4. Lock down the threat landscape<br>If the account does not need to mail the whole internet, restrict outbound (organization-only, or allow list). Stolen SMTP then cannot phish random addresses. If you have a stable office\/VPN IP, restrict mail-client access to that IP.<\/p>\n\n\n\n<p>5. The server that sends mail acts as a part of the mailbox<br>A web server with the app password in some form has a copy of the key. Restrict SSH to only one IP and still assume that file can leak. <\/p>\n\n\n\n<p>6. Highlight the critical alerts<br>Filter provider alerts (login, SMTP, suspicious) to Inbox, flag them, stop other filters. Do not let \u201csmart notification\u201d sorting bury them. One ignored SMTP alert is often the last warning before a volume spike. Set a rule to flag and add a Critical label and anything you can do to act to prevent.<\/p>\n\n\n\n<p>7. Check all the logs<br>Web login history can be clean while SMTP Auth logs is not. Check outbound \/ SMTP \/ \u201csuspicious login\u201d with protocol and IP. Check for any impossible travel authentication successes. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Incident response : After the hit<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Revoke app passwords and sessions, reset the mailbox password, confirm MFA<\/li>\n\n\n\n<li>Check forwarding, filters, delegates, recovery email\/phone<\/li>\n\n\n\n<li>Restrict outbound until the logs stabilize. <\/li>\n\n\n\n<li>Save one full EML (headers) and the AUTH IPs for investigation and escalation if necessary<\/li>\n\n\n\n<li>Check domain blocklists (Spamhaus, MX Toolbox). A short burst often never lists you. Recovery is: stop the abuse, send only real mail, do not spray apologies to random victims<\/li>\n\n\n\n<li>If it is a known recipient, advise them of a Business email compromise and to disregard and relay that everything has been mitigated. <\/li>\n\n\n\n<li>Public lists can stay green while Google still files some of that wave as spam. That fades once the spam quiets down. <\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>You cannot unsend phishing. You can stop the next hour.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Baseline from small to big teams<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>MFA on all web accounts<\/li>\n\n\n\n<li>No unused app passwords, thoroughly document<\/li>\n\n\n\n<li>Tag alerts from your provider as high priority<\/li>\n\n\n\n<li>Glance at SMTP \/ suspicious-login logs monthly<\/li>\n\n\n\n<li>Any hosted mail provider will not assign you a human investigator. The controls above are the response. Use them before the \u201cnew login activity\u201d mail is the only thing standing between a probe and a blast.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your mailbox can be abused without anyone opening webmail. Most people treat a hacked email as: someone logged into Gmail in a browser. A lot of real incidents are quieter. Someone gets a SMTP password, sends mail as you, and never touches the inbox. SMTP is how servers and apps send mail: WordPress, a monitoring [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[10],"tags":[11,8],"class_list":["post-316","post","type-post","status-publish","format-standard","hentry","category-phishawareness","tag-compromised-smtp","tag-phishingawareness"],"_links":{"self":[{"href":"https:\/\/rjsecure.com\/index.php?rest_route=\/wp\/v2\/posts\/316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rjsecure.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rjsecure.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rjsecure.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rjsecure.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=316"}],"version-history":[{"count":1,"href":"https:\/\/rjsecure.com\/index.php?rest_route=\/wp\/v2\/posts\/316\/revisions"}],"predecessor-version":[{"id":317,"href":"https:\/\/rjsecure.com\/index.php?rest_route=\/wp\/v2\/posts\/316\/revisions\/317"}],"wp:attachment":[{"href":"https:\/\/rjsecure.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rjsecure.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rjsecure.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}