Cybersecurity · Named client
A month of impersonation, ended in three days
Two active phishing campaigns were running against a law firm's client from a single impersonation domain. Nobody had found the infrastructure behind it. Analysis took one day; takedown took three.
At a glance
- Client
- CG Legal & Real Estate
- Practice
- Cybersecurity
- Analysis
- 1 day
- Takedown
- 3 days
- Exposure before
- Over 1 month
DNS · Certificate transparency · OSINT · Monitoring · Alerting
The situation
The attack had been running for over a month
A legal and real-estate consultancy discovered that someone was impersonating the firm to target one of its clients. Two separate phishing campaigns were live, and they had been running for more than a month before anyone connected them to a single source.
The firm's real exposure was wider than the incident in front of them. The same infrastructure could be pointed at any client on their book, and a duplicated campaign against a second client would have looked identical from the outside — which is the difference between an incident and a pattern.
What we did
Four steps, in this order.
Traced both campaigns to one origin
The two campaigns looked separate. One day of analysis established that both came from the same impersonation domain, which changed the problem from two incidents into one piece of infrastructure.
Mapped the hidden assets
Behind the visible domain sat seven further assets holding the campaign up. None of them were known to the client. Taking down only what was visible would have left the operation intact.
Escalated to the authorities
Once the origin was documented, the case was escalated to the relevant authorities with the evidence organised for them rather than handed over raw.
Left monitoring behind
A monitoring platform now watches for domain changes and new registrations, polling every ten seconds, so a duplicated campaign surfaces in seconds rather than after a month.
Results
The numbers, as measured.
The takeaway
What this case actually shows
The month of exposure was not a detection failure by the firm — it was the absence of anyone looking. The seven unknown assets are the point: an organisation cannot defend a surface it has never been shown, and the visible domain was the smallest part of the problem. That is why the cybersecurity practice starts with discovery before it starts with fixing.
Start here
Have a version of this problem?
Describe the problem in a few lines. You get a written reply with a first read on it, whether or not there is an engagement in it. The message is sent from this page — no email client, no third-party form service, no trackers.