On February 4, 2019, it was brought to a user?s attention that the user?s email account had been used to send emails that appeared to be suspicious. Internal IT and outside consultants determined that someone unknown had accessed the user?s email account and used it to send emails with a fraudulent purpose. No evidence of data exfiltration or any other access to the Organization?s resources were found. The investigation revealed a number of suspicious logins to other of the organization?s email inboxes but there was no evidence that these inboxes were used for sending similar messages.

