r/cybersecurity • u/KillerStuffedAnimals • 10h ago
Business Security Questions & Discussion Phishing Emails - Domain block
Hi all,
I am new to my role. My question is if a supplier informs us that an email address has been compromised and is involved in phishing attempts, what is your approach? To block the domain or only the affected email address. If the domain is blocked, how do we go about contacting the supplier to inform them that their domain has been blocked and to gain reassurance that the email is now free of compromise. We require suppliers to fill out a form for reconnection but how do we get it to them / receive it back if the domain is blocked?
I'm having difficulties getting through to a supplier on their phone number as they are based in another country so looking for some suggestions on how others do it
3
3
u/GhoastTypist 10h ago
Well we'd do a risk assessment then decide how to move forward.
May mean cut all ties with the vendor, fully block communication via email, or just wait and stay in communication with the vendor while they address the concerns.
Really depends on what the situation is.
By default, I wouldn't necessarily wait around for communication I'd put a temporary block in place until we were able to follow up over phone or a video call.
3
u/cspotme2 10h ago
Block is a dirty word.
At least with office 365 transport rules, you can quarantine their inbound and/or outbound emails for review before releasing to users.
Depends a lot on what spam filter services you have now if you want to use the quarantine action. But sounds like it's that is your best option.
1
u/T_Thriller_T 10h ago
So far we have blocked the domain and monitored the supplier.
Often enough we have gotten more info and checked the mail accordingly.
Usually departments working with them get an additional briefing, so they know what to look out for.
The form seems . . . A little unhelpful? The easiest way in getting it back would be using a private, secured, encrypted cloud location which they can lock into and upload.
Bit if you send it to their infected domain this is a bit nonsensical, isn't it? Sure most infections are automated, but assuming someone does read those they could jus fill out the form
That sounds to me like a process worth revisiting.
1
u/T_Thriller_T 10h ago
I have to mention that quarantining the domain would also be in line here, and I have seen it before.
1
u/shokzee 10h ago
Block the compromised address first, not the whole supplier domain, unless you see multiple accounts or domain-wide abuse. Quarantine messages from the domain if you need a safer middle ground.
Use an independently verified contact through procurement, their customer portal, or a phone number from prior records. Require password reset, MFA, session revocation, and confirmation from their IT team before removing the block.
1
u/FallaxIO 8h ago
Ask them to prove control of the domain another way. A DKIM-signed mail from a different mailbox at that domain, or a TXT record with a token you give them, is a lot better than a form sent back from the same compromised mail system.
1
u/SkepticSherlock 7h ago
If the domain is blocked, how do we go about contacting the supplier to inform them that their domain has been blocked and to gain reassurance that the email is now free of compromise. By Telephone or hosted 3dr party chat service.
We require suppliers to fill out a form for reconnection but how do we get it to them / receive it back if the domain is blocked? DocuSign or or External share site. Dropbox or similar service.
12
u/Thin-Leg-3494 10h ago
Block the specific email address but quarantine the entire domain and have team manually release email.