Introducing Automated Account Takeover (ATO) Remediation Functionality

October 15, 2021

Detecting and remediating account takeovers is a top concern for organizations, as compromised accounts can lead to damaged brand reputation, regulatory obligations, lost user productivity, and legal repercussions. And while compromised accounts can happen in a variety of ways, credential phishing remains the most popular. New data from the Abnormal Q3 2021 Email Threat Report shows how prevalent credential phishing is, as it continues to make up a growing share of advanced attacks—from 66% of advanced attacks in Q4 2020 to over 73% of attacks in Q2 2021.

Perhaps most indicative of the way threat actors are turning their attention to compromising accounts, our data also showed a 671% increase in the weekly average of brute force attacks. These attacks occur when cybercriminals target an account and programmatically test character combinations to determine the account password. With poor password hygiene and a lack of multi-factor authentication, these attacks can quickly lead to compromise.

Introducing Automated Account Takeover Attack Remediation

With this increase in threat actor attention toward compromising accounts, Abnormal is focused on protecting our customers from this potentially high-profile threat. As such, we are pleased to announce that our new Automated Account Takeover (ATO) Remediation functionality is available.

Now, when Abnormal detects a potentially compromised account, Microsoft Office 365 customers have the choice to either manually or automatically use Microsoft Active Directory APIs to remediate account takeovers.

Too fast travel notice

This functionality allows them to sign affected users out of active sessions, disable their accounts, and optionally force password resets. The security team can then work with the affected user to reset their password and re-enable their account. An example of this functionality is shown here.

Compromise notice

Once the automatic remediation setting is enabled, Abnormal will perform these actions immediately upon detection, no matter the time of day or night, to prevent further threat actor access to the account.

Eliminate Risk Due to Dwell Time

The longer a bad actor has access to an account, the wider the opportunity window is to perform malicious activities, including data exfiltration, siphoning off funds, sending lateral phishing emails, and even planting secondary malware or advanced persistent threats (APTs).

Lateral, east-west traffic often goes undetected by traditional defenses that miss out on the device and sign-in location data signals. In contrast, with an API architecture approach, Abnormal detects east-west traffic to catch internal account compromises. According to the research available in the Q1 2021 Email Threat Report, employees are four times more likely to engage attackers through lateral phishing attacks from compromised internal accounts than credential phishing attacks from external accounts.

Ato analysis overview

Abnormal account takeover remediation further reduces the meantime to respond (MTTR) by enabling administrators to perform investigations and remediation actions from within a single tool. This prevents the need to jump into yet another console such as Microsoft Azure.

Key Benefits of Automated Account Takeover (ATO) Remediation

Your time as a security analyst is valuable. With Abnormal Account Takeover Remediation, you can save time and increase visibility—making it easier than ever to ensure that your organization is protected. Other key benefits include:

  • Rapidly respond to account compromises through auto-remediation by logging out of active sessions, blocking access, resetting passwords, and helping affected users to regain access.

  • Detect compromised accounts instantly across internal employees and external partners.

  • Review explainable attack analysis to understand why an account was determined to be compromised.

Curious to see how Abnormal Account Takeover Remediation could work for you? Request a demo today.

Image

Prevent the Attacks That Matter Most

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Demo 2x 1

See the Abnormal Solution to the Email Security Problem

Protect your organization from the attacks that matter most with Abnormal Integrated Cloud Email Security.

Related Posts

B 05 11 22 Scaling Out Redis
As we’ve scaled our customer base, the size of our datasets has also grown. With our rapid expansion, we were on track to hit the data storage limit of our Redis server in two months, so we needed to figure out a way to scale beyond this—and fast!
Read More
B 05 17 22 Impersonation Attack
See how threat actors used a single mailbox compromise and spoofed domains to subtly impersonate individuals and businesses to coerce victims to pay fraudulent vendor invoices.
Read More
B 05 14 22 Best Workplace
We are over the moon to announce Abnormal has been named one of Inc. Magazine's Best Workplaces of 2022! Learn more about our commitment to our workforce.
Read More
B 05 13 22 Spring Product Release
This quarter, the team at Abnormal launched new features to improve lateral attack detection, role-based access control (RBAC), and explainable AI. Take a deep dive into all of the latest product enhancements.
Read More
B 05 11 22 Champion Finalist
Abnormal has been selected as a Security Customer Champion finalist in the Microsoft Security Excellence Awards! Here’s a look at why.
Read More
Blog series c cover
When we raised our Series B funding 18 months ago, I promised our customers greater value, more capabilities, and better customer support. We’ve delivered on each of those promises and as we receive an even larger investment, I’m excited about how we can continue to further deliver on each of them.
Read More
B 05 09 22 Partner Community
It’s an honor to be named one of CRN’s 2022 Women of the Channel. Here’s why I appreciate the award and what I love about being a Channel Account Manager at Abnormal.
Read More
B 05 05 22 Fast Facts
Watch this short video to learn current trends and key issues in cloud email security, including how to protect your organization against modern threats.
Read More
B 05 03 22
Like all threats in the cyber threat landscape, ransomware will continue to evolve over time. This post builds on our prior research and looks at the changes we observed in the ransomware threat landscape in the first quarter of 2022.
Read More
B 04 28 22 8 Key Differences
At Abnormal, we pride ourselves on our excellent machine learning engineering team. Here are some patterns we use to distinguish between effective and ineffective ML engineers.
Read More
B 04 26 22 Webinar Re Replacing Your SEG
Learn how Microsoft 365 and Abnormal work together to provide comprehensive defense-in-depth protection in part two of our webinar recap.
Read More
Blog mitigate threats cover
Learn about the most common socially-engineered attacks and why these tactics are still so successful—despite a growing awareness from employees.
Read More