DHDatara Hub

Cybersecurity · Named client

A month of impersonation, ended in three days

Two active phishing campaigns were running against a law firm's client from a single impersonation domain. Nobody had found the infrastructure behind it. Analysis took one day; takedown took three.

At a glance

Client
CG Legal & Real Estate
Practice
Cybersecurity
Analysis
1 day
Takedown
3 days
Exposure before
Over 1 month

DNS · Certificate transparency · OSINT · Monitoring · Alerting

The situation

The attack had been running for over a month

A legal and real-estate consultancy discovered that someone was impersonating the firm to target one of its clients. Two separate phishing campaigns were live, and they had been running for more than a month before anyone connected them to a single source.

The firm's real exposure was wider than the incident in front of them. The same infrastructure could be pointed at any client on their book, and a duplicated campaign against a second client would have looked identical from the outside — which is the difference between an incident and a pattern.

What we did

Four steps, in this order.

01

Traced both campaigns to one origin

The two campaigns looked separate. One day of analysis established that both came from the same impersonation domain, which changed the problem from two incidents into one piece of infrastructure.

02

Mapped the hidden assets

Behind the visible domain sat seven further assets holding the campaign up. None of them were known to the client. Taking down only what was visible would have left the operation intact.

03

Escalated to the authorities

Once the origin was documented, the case was escalated to the relevant authorities with the evidence organised for them rather than handed over raw.

04

Left monitoring behind

A monitoring platform now watches for domain changes and new registrations, polling every ten seconds, so a duplicated campaign surfaces in seconds rather than after a month.

Results

The numbers, as measured.

7hidden assets found behind one domain
0of them known to the client beforehand
1 dayfrom engagement to identified origin
3 daysfrom identification to takedown

The takeaway

What this case actually shows

The month of exposure was not a detection failure by the firm — it was the absence of anyone looking. The seven unknown assets are the point: an organisation cannot defend a surface it has never been shown, and the visible domain was the smallest part of the problem. That is why the cybersecurity practice starts with discovery before it starts with fixing.

Read about the Cybersecurity practice →

Start here

Have a version of this problem?

Describe the problem in a few lines. You get a written reply with a first read on it, whether or not there is an engagement in it. The message is sent from this page — no email client, no third-party form service, no trackers.

We use your message to reply to you. Nothing else — no list, no third parties.