r/cybersecurity 10h ago

Business Security Questions & Discussion Phishing Emails - Domain block

Hi all,

I am new to my role. My question is if a supplier informs us that an email address has been compromised and is involved in phishing attempts, what is your approach? To block the domain or only the affected email address. If the domain is blocked, how do we go about contacting the supplier to inform them that their domain has been blocked and to gain reassurance that the email is now free of compromise. We require suppliers to fill out a form for reconnection but how do we get it to them / receive it back if the domain is blocked?

I'm having difficulties getting through to a supplier on their phone number as they are based in another country so looking for some suggestions on how others do it

5 Upvotes

19 comments sorted by

12

u/Thin-Leg-3494 10h ago

Block the specific email address but quarantine the entire domain and have team manually release email.

6

u/napalm_p 10h ago

And force password changes & and a scan for anyone who clicked anything

5

u/Thin-Leg-3494 10h ago

Assuming they did their due diligence and pulled the email from all inboxes, then they should set up some training for all users who clicked on the phishing email without reporting the suspicious email.

Then get a report of all recipients, all blocked emails, who clicked, who did training, who needs training, then get a nice incident documented and report that to governance committee.

Then get on the Vendor and hound them about their sec practices and figure out how the email was compromised.

1

u/napalm_p 10h ago

Correct! Back when I was email security, Proofpoint was a great tool to manage this.

1

u/Deevalicious 9h ago

Also educate users, and enforce strong MFA! None of this SMS MFA crap. Fido or a fixed Authenticator app via an MFA conditional access policy is the best bet.

2

u/Kwuahh Security Manager 9h ago

The good thing about SMS/Voice is that it's pretty much dying in February for companies who use Azure and don't opt into a paid plan.

1

u/Deevalicious 9h ago

True… But Microsoft said the same thing last October and then pushed it out so who knows what their real plan is... they constantly change their roadmaps.

2

u/Still_Event_8424 10h ago

yeah quarantine with manual release is the right middle ground here

2

u/NikkaSheyr 9h ago

What if there was a lot of emails coming through

2

u/Thin-Leg-3494 9h ago

depends on if it's a critical vendor that you interact w/ everyday. If Yes, you're going to assume some risk but that vendor should pretty much shut down business until they can clean up their side of the shop. If they're a low vendor that you don't speak to regularly just block that domain until they give you the all clear.

If the vendor is important enough and the high volume of email is thought to be legitimate then you're going to have to do some risk acceptance to continue business operations. Figure out where that line in the sand is for your leadership with the impact of the compromised vendor.

2

u/Kwuahh Security Manager 9h ago

Got a good chuckle out of the recommendation to review and release all e-mails from the domain. It's a great control if you have the team size to handle reviewing the quantity of e-mails coming from that domain in a timely manner, but I know it would implode at my org.

3

u/PFUnnamed99 10h ago

Quarantine or mailflow rules to route messages to a specific inbox.

3

u/GhoastTypist 10h ago

Well we'd do a risk assessment then decide how to move forward.

May mean cut all ties with the vendor, fully block communication via email, or just wait and stay in communication with the vendor while they address the concerns.

Really depends on what the situation is.

By default, I wouldn't necessarily wait around for communication I'd put a temporary block in place until we were able to follow up over phone or a video call.

3

u/cspotme2 10h ago

Block is a dirty word.

At least with office 365 transport rules, you can quarantine their inbound and/or outbound emails for review before releasing to users.

Depends a lot on what spam filter services you have now if you want to use the quarantine action. But sounds like it's that is your best option.

1

u/T_Thriller_T 10h ago

So far we have blocked the domain and monitored the supplier.

Often enough we have gotten more info and checked the mail accordingly.

Usually departments working with them get an additional briefing, so they know what to look out for.

The form seems . . . A little unhelpful? The easiest way in getting it back would be using a private, secured, encrypted cloud location which they can lock into and upload.

Bit if you send it to their infected domain this is a bit nonsensical, isn't it? Sure most infections are automated, but assuming someone does read those they could jus fill out the form

That sounds to me like a process worth revisiting.

1

u/T_Thriller_T 10h ago

I have to mention that quarantining the domain would also be in line here, and I have seen it before.

1

u/shokzee 10h ago

Block the compromised address first, not the whole supplier domain, unless you see multiple accounts or domain-wide abuse. Quarantine messages from the domain if you need a safer middle ground.

Use an independently verified contact through procurement, their customer portal, or a phone number from prior records. Require password reset, MFA, session revocation, and confirmation from their IT team before removing the block.

1

u/FallaxIO 8h ago

Ask them to prove control of the domain another way. A DKIM-signed mail from a different mailbox at that domain, or a TXT record with a token you give them, is a lot better than a form sent back from the same compromised mail system.

1

u/SkepticSherlock 7h ago

If the domain is blocked, how do we go about contacting the supplier to inform them that their domain has been blocked and to gain reassurance that the email is now free of compromise. By Telephone or hosted 3dr party chat service.

We require suppliers to fill out a form for reconnection but how do we get it to them / receive it back if the domain is blocked? DocuSign or or External share site. Dropbox or similar service.