8 min read
A consent phishing case, minute by minute
A real case with the names changed: from the click at 2:38 am to the CFO call at 7:05.
Dana Reyes
Lead analyst

This is a case from July, shared with the customer's permission and with names changed.
02:38 to 02:44
An accounts payable manager clicked a link in an invoice email and approved an app called QuickSign PDF. Within three minutes the app created three inbox rules that hid any email containing wire, ACH or invoice.
02:51
Wardell grouped six alerts into one case and paged the on-call analyst, who acknowledged at 02:53, revoked the app consent and removed the rules by 03:10.
07:05
The hand-off note reached the customer's Slack at 8 am. Their controller called the CFO at 7:05 because the note named a pending wire of $184,000. It was stopped.
Send us one week of logs. We send back what we found.
Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.