You Can't Reset a Reputation
Fictional company: Ironwood Mechanical
A commercial mechanical contractor was never broken into and never had a dollar stolen from its accounts. A phished field-tech password, a domain anyone could forge, and an IT vendor who sold configuration as though it were a product turned the company's own email into a weapon against its customers, its suppliers, its bank, and its attorney. The abuse kept going after every password was changed. The controls that would have stopped it were almost all free. Nobody was there to say so.
Ironwood Mechanical found out it had a problem when its own supply house called to report it. Emails from Ironwood had been hitting the supplier's inbox all morning: fake invoices, and a link asking their staff to log in. The supplier figured one of Ironwood's computers had a virus and left it at that.
It was not a virus, and it was not one computer. Ironwood's email was being used to phish its customers, its suppliers, its bank, and its attorney, and the messages were landing because they genuinely came from Ironwood. It went on for weeks. It kept happening after every password in the building was reset, because the passwords were never the problem.
To understand how a company gets taken apart by its own email, start with what Ironwood was, and what the company it trusted had built.
The company
Ironwood Mechanical does commercial HVAC and plumbing. Eighty-five employees, twenty years in business. Six people in the office. Everyone else is in a truck: service techs on maintenance contracts, install crews on job sites for the general contractors Ironwood subs under. They hold service agreements on a couple of school districts, a few office parks, and a regional hospital. Revenue runs about eighteen million a year on thin margins, so cash flow matters.
Sal Marchetti built it from one van. He is a master tradesman and a good businessman, and he has never spent a minute thinking about email security, because nobody ever told him it was a thing he owned. That absence of awareness, and not any failing of Sal's, is the whole point of this story.
A vendor, not an advisor
Ironwood's IT is handled by Delmar IT Solutions, a regional shop that started fixing broken computers and grew into managed services. Delmar keeps the servers patched, the workstations running, the printers online, and email flowing. They are good at that. Security is a different trade, and it is not the one Delmar came up in.
Delmar does sell a "security package," and their rep, Kyle, brings it up. The trouble is how he brings it up. Kyle talks about threats and breaches and layers of protection in a way that lands, to a man who fixes chillers for a living, like every other salesman trying to grow the invoice. Sal likes Kyle. Sal also assumes that anything Kyle is enthusiastic about is something Kyle makes money on. So the security conversation always ended the same way: a nod, a "let me think about it," and nothing changing.
Nobody in that room was equipped to see the real split. Some of what Kyle was selling was real security work worth paying for. And some of it was not a product at all. Two of the settings that mattered most, multi-factor authentication and email authentication, are not something you buy. They are configuration, the kind of thing a competent advisor turns on as part of doing the job. But they were bundled into the same "package," pitched with the same salesman's urgency as everything else. So the free basics got refused right alongside the paid extras, and the refusal looked, to everyone involved, like a budget decision.
Sal never turned down security. He was never told which parts were the cheap seatbelt and which parts were the luxury upgrade. There was no one in his world whose job was to draw that line.
Everybody had an email
Look at what Delmar built, because everything the attacker did ran on choices already made here.
Every one of Ironwood's eighty-five people has a full company email account. Nobody ever decided the install crews needed to send and receive mail with the outside world. A mailbox is simply what everyone got when they were hired. A service tech who needs a schedule and a timecard has the same internet-facing inbox as the controller. The result is that the entire company is reachable by any stranger with an email address.
And the crews get phished constantly. Everyone in the trades does. What made Ironwood worse than average is that when a tech got a suspicious email, he would forward it to a few coworkers asking "is this real?" The bait circulated inside the company like a chain letter.
Passwords were simple and reused, because no one had ever been given a tool to make them anything else. There was no password manager. Nobody can hold sixteen random characters in their head for forty different logins, so people did the only thing available to them: they picked something easy and used it everywhere. That is a tool problem before it is a discipline problem.
There was no multi-factor authentication anywhere, the second check most people know as the code that comes to your phone. A password was the only thing standing between the outside world and an Ironwood account.
There was no SPF, DKIM, or DMARC. Those are the settings that let the rest of the internet verify that an email claiming to come from ironwoodmech.com actually did. Without them, anyone can send email as Ironwood, and the servers that receive it have no reliable way to prove it is fake. They are left guessing from spam-filter reputation and rules of thumb, and forged mail routinely slips past. Nobody had ever told Sal these existed. They are invisible right up until the day they are the only thing that matters.
And the firewall, the box Sal pointed to when he said he was covered, was a consumer router from a big-box store. It was protecting an eighteen-million-dollar business. A real commercial firewall felt expensive, so the small one stayed. That router is the whole story in one object: cheap hardware standing in for a decision nobody knew was theirs to make.
Ironwood had technology. It had no people watching it and no process governing it. They bought tech because tech is what you buy now.
The key that got copied
On an ordinary Tuesday, a service tech named Ray opened an email between calls that said his mailbox was full and he needed to re-verify to keep receiving messages. He clicked. The page looked exactly like the Microsoft login he saw every morning. He typed his email and his password. The page spun, said something about a sync error, and he went back to work. He thought nothing of it, because nothing broke.
There was no second step to catch it, so Ray's password was a working key to his account. And the person who took it was not the person who would eventually use it.
This is how the business works now, and it defeats the instinct every owner has. The person who phished Ray was a broker. His whole business is stealing access and selling it. He logged into Ray's mailbox, read enough to confirm what he had (a real company, real customers, no MFA, no DMARC, a soft target), and sold it on a criminal market to someone else. He never sent a fake invoice. He copied a key, sold it, and moved on to the next door.
Weeks passed. Nothing happened. If anyone at Ironwood had noticed the strange login, they would have changed Ray's password and called it solved. It would not have been solved. The key had already changed hands.
The company, weaponized
The buyer went to work in two stages, and the second stage is the one that outlived every fix Ironwood tried.
In the first stage, the attacker worked from Ray's real account. Real name, real address, real signature, real history of past messages to reply into. Ray's mailbox held the company address book, so the attacker sent the same login trick to the office: dispatch, accounts payable, the controller. Each of them typed a password, the same way Ray had, because the request came from a coworker. And because people reused passwords everywhere, each account the attacker caught opened more than one system.
Then the attacker made sure nobody would notice. Inside each mailbox, they set up inbox rules, the same automatic filters anyone can create to sort their mail. These ones quietly deleted the replies and the bounce-backs, so when a confused customer wrote back to ask "did you really send this?", the employee whose account sent it never saw the reply. The mailboxes were working against their own owners.
In the second stage, the attacker stopped needing an account at all. Ironwood had never set up email authentication, so anyone could forge ironwoodmech.com directly. Not a lookalike address that resembles Ironwood. The actual domain. Email that told every server that received it that it came from Ironwood, with nothing anywhere able to prove otherwise. The attacker sent fake invoices and login traps, all appearing to come from Ironwood, to the people who deal with Ironwood every day and had no reason to doubt a message from them: the supply house, the other subcontractors on shared jobs, the general contractors Ironwood worked under, the bank, and the company's own attorney.
Then Delmar found the compromise and reset the passwords. Ray's account, the office accounts, all of it. And the abuse kept going, for two reasons. The inbox rules were still there, because resetting a password does not remove the rules an attacker already created. And forging the domain never needed a password in the first place. You cannot reset your way out of a domain anyone can impersonate. The one control that would have shut the forgery down, DMARC set to reject, was a setting Ironwood never had, and no password reset creates it.
What it did to everyone else
The damage never touched Ironwood's own servers. It fell on the people who trusted Ironwood, and then it worked its way back.
The supply house that first flagged the problem got caught by it too. Someone in their accounts-payable department, on a different day, clicked an Ironwood invoice and entered their login. When they traced it back, the source was Ironwood again. They stopped extending Ironwood thirty-day terms and moved the account to cash on delivery. A company that had always paid for materials on thirty days now had to pay cash up front for every rooftop unit and every length of pipe. The working-capital cushion that let Ironwood float between finishing a job and getting paid for it was gone.
Ironwood's own outgoing email started disappearing. When a domain is used to send waves of phishing, the big mail providers add it to spam blocklists, and after that the company's legitimate mail, its bids, its quotes, its real invoices, quietly lands in customers' junk folders or bounces. For a contractor who wins work by emailing estimates, that is a slow leak with no alarm attached. You do not find out you lost the job. You stop getting called back, and you never learn why. This kept going for months, because a domain's reputation does not reset when the passwords do. Even standing up a brand-new domain would not have fixed it overnight, since a new address earns trust slowly and every old bid and business card still points at the old one.
The compromised mailboxes were also a way into everything else. Most systems let you reset a forgotten password by sending a link to the email address on file, so whoever controls the mailbox can quietly take over the accounts tied to it. The accounting software, the supplier portals, the account used to sign documents, all of it was reachable from an inbox the attacker already held.
The mailboxes also held years of files that were never meant to leave the building: employee tax forms with Social Security numbers, customer records, banking details, scanned contracts. When personal information like that is copied out of a company, the law in most states requires the company to notify everyone affected, at its own expense. On top of everything else, Ironwood now owed breach letters to its own employees.
The legal exposure ran outward, too. A general contractor's controller had wired money against an invoice that came from Ironwood's domain. A supplier had been phished in Ironwood's name. Those parties took their losses, and then they looked to Ironwood to make them whole. Ironwood carried no cyber insurance to defend any of it. Insurance is not something an IT company sells, so it never came up, and there was no one else in the room to raise it.
Then the questionnaires arrived. The general contractors and the facility managers Ironwood worked for started sending vendor security questionnaires, the standardized forms a company sends its suppliers to confirm they are safe to do business with. Do you enforce multi-factor authentication? Do you have endpoint monitoring? Tested backups? Email authentication? Cyber insurance? An incident response plan? Ironwood could not answer a single line with a yes. It came off the approved-vendor lists, and it lost contracts the attacker had never touched. The incident cost Ironwood a season. The questionnaires cost it customers who had stayed loyal through the season.
What Ironwood lost
Ironwood stayed in business. The damage still landed in several places at once.
They lost their credit terms with the supplier who knew them best, which turned every purchase into a cash-flow decision. They lost the reliability of their own email, which is how a bid-driven business talks to the people who pay it. The approved-vendor lists that fed them work dropped them, and the accounts went with the listings. They took on legal exposure from businesses defrauded in their name, with no insurance behind them. The credit squeeze and the slow receivables together put real pressure on payroll.
The loss that does not show up on a balance sheet is the one that lasted longest. Ironwood works in a tight trade community where everyone knows everyone, and word travels. For a while, the safest assumption about a message from Ironwood was that it might be fake, and the people who had been burned by one did not forget it. In that world, trust is the working capital, and it is the slowest thing to rebuild.
People
Nobody at Ironwood owned security, and nobody advised Ironwood on it. There was a salesman, and there was an owner who could not hear the salesman as anything but a salesman. The gap between them is where this started.
A company of eighty-five does not need a chief information security officer and cannot justify one. What it needed was a translator: an advisor, a fractional security lead, or an IT partner with real security credentials, whose job is to walk in and say "these five things are basic, they are mostly free, we do them this week, and these other three are worth paying for, here is why." That role is the difference between a vendor who sells you boxes and a partner who tells you what you are missing. For a shop this size, a one-time assessment is where you start.
Ironwood also gave every employee a full, internet-facing mailbox, when most of the staff only ever needed to hear from inside the company. A field tech who gets a schedule and submits a timecard can be set up with an internal-only account, one that cannot receive mail from the outside world at all. That closes the door on the stranger in another country trying to phish him, without taking away the email he actually uses. It is a configuration choice, and Ironwood was never guided to make it.
And the crews were never taught what they were looking at. They forwarded phishing to each other because no one had ever shown them how to recognize it or where to report it. Awareness training for a company this size is one of the cheapest things it can buy, and one of the most useful.
Process
Ironwood had no rule for verifying a change to payment details. When an email asks to change bank account information, whether it comes from a vendor, a customer, or the owner himself, there has to be a step that leaves email entirely: a phone call to a known number, confirmed out loud. That one habit protects the company in both directions, against a fraud aimed at Ironwood and against Ironwood being used to defraud someone else. It costs nothing. It has to be written down and expected, because in the moment, under pressure, people do what the process tells them to do. Ironwood had no process, so people did whatever the email said.
There was no one qualified to weigh essential against optional. Somebody in the building, or on retainer, has to be able to read the IT vendor's proposal and separate the hygiene from the luxuries. Without that, "security" is just a price, and a price is easy to say no to.
And there was no incident response plan, which is why the response was incomplete. When the compromise surfaced, the instinct was to reset the passwords and declare it handled. Nobody knew to hunt for the inbox rules the attacker had left behind, to turn on email authentication so the domain could no longer be forged, or to get the company off the spam blocklists. A plan written on a calm day would have listed those steps. The panic of a bad week did not.
Technology
Every item here would have blunted or stopped the attack, and the striking thing is how little of it costs money.
Multi-factor authentication on every account. It would have made Ray's stolen password far less useful, because signing in would have taken a second step the attacker did not have. MFA stops the ordinary, bulk version of this attack, the kind that harvests passwords by the thousand. Worth knowing the limit, because it is exactly where a real advisor earns their keep: a convincing fake login page can sometimes capture that second step too, so the strongest form of MFA uses a physical key or a passkey rather than a code you type. Any MFA is a large step up from a password alone. It is included in the Microsoft plans a company like this already pays for, and it belongs on every account, because every account signs in through the same page.
Email authentication: SPF, DKIM, and DMARC set to reject. This is the one that matters most here, and it is a configuration, not a product. It would have stopped the domain forgery, the half of the attack that kept going after every password was reset. Publishing the records is trivial. Getting all the way to reject safely takes a few weeks of first watching who legitimately sends mail as your domain, so you do not block your own invoices on the way to closing the door on forgeries. Rushing that step breaks your own mail. Skipping it entirely is how Ironwood's domain stayed forgeable. Staging it correctly is exactly the kind of work a real advisor does and a box-seller does not.
One caution, so you set it up with clear eyes. This protects your exact domain and nothing else. It stops an attacker from forging mail as ironwoodmech.com, which is the dangerous move in this story. It does not stop someone from buying a similar-looking domain like ironwood-mechanical.com, and it does not stop mail sent from an account an attacker has actually logged into. It shuts one specific door, the most important one here, and the other items on this list cover the rest.
A password manager removes the reason weak, reused passwords exist. It is inexpensive, and it does more for real-world security than any amount of lecturing about password hygiene, because it fixes the cause instead of blaming the symptom.
Internal-only accounts for field staff shrink the target from eighty-five mailboxes to the handful that actually need to reach the outside world.
A business-grade firewall that someone monitors, in place of the big-box router in the closet. This one is a real purchase, and a modest one, and it buys a front door that keeps records a human being actually reads.
Endpoint detection with monitoring behind it, software that watches each computer for signs of a takeover. Without a human who responds to what it finds, it is just a log nobody reads.
Domain and email reputation monitoring, so you learn your email is landing in spam within days, instead of months later in the shape of bids that never got answered.
Add it up. The controls that would have prevented this attack are, nearly all of them, configuration or low cost. Money was the smaller gap. The bigger one was the person who could tell them which of these was which.
What would have stopped it
| Control | Cost | Where it changes the outcome |
|---|---|---|
| MFA on every account | Free (usually included) | A stolen password alone is no longer enough to log in, which stops the common bulk version of this attack. |
| SPF, DKIM, DMARC at reject | Free (configuration) | The domain cannot be forged. The forgery fails, and resetting passwords actually ends the abuse. |
| Password manager | Low | Weak, reused passwords stop being the only option employees have. |
| Internal-only field accounts | Free (configuration) | The target shrinks from 85 mailboxes to the few that need outside mail. |
| Out-of-band verification of payment changes | Free (process) | Redirected-payment fraud fails, whether aimed at Ironwood or sent in Ironwood's name. |
| Business-grade firewall, monitored | One-time purchase | A real front door with real records replaces the big-box router. |
| Endpoint detection with monitoring | Ongoing service | Someone sees the takeover instead of a log nobody reads. |
| Security awareness training | Low | Crews can tell the bait from the real thing, and stop forwarding it. |
Two things belong ahead of any tool on that list. First, a security advisor or fractional security lead, the person who separates the free basics from the paid extras. Second, cyber insurance, which does not prevent the attack but pays for the legal defense and cleanup when someone who lost money in your name comes looking.
No single control is a guarantee. But this attack needed two doors open at once: a front door with no second lock, and a domain anyone could forge. Close either one and it does not happen. Ironwood had left both open, and both were nearly free to close.
What to do Monday
Find out whether your domain can be forged today. Ask your IT provider, or have someone check your domain's SPF, DKIM, and DMARC records. If DMARC is not set to reject, someone can send email as your company, to your customers, right now. This is a configuration, not a purchase, so the honest question to your vendor is why it is not already done.
Turn on multi-factor authentication everywhere it is not, and confirm it is enforced on every login path. Every account, every way in. A field tech's password is what started this story.
Get the list of every mailbox and ask who actually needs outside email. Set the rest to internal-only. A phished field account should not be able to reach your customer list or your bank.
Run the vendor test. Ask your IT provider to split their last proposal into two columns: basic configuration you should already have, and paid services worth considering. A provider who can draw that line clearly is an advisor. A provider who cannot, or will not, just told you what kind of vendor you have.
Discussion questions
If someone spoofed your domain to your customers today, would you know? Have you set up SPF, DKIM, and DMARC, and is DMARC set to reject rather than just watching?
Who in your company has a mailbox an outsider can reach, and does every one of them need it? Could a single phished field employee's account reach your customer list or your bank?
When your IT vendor quotes you "security," can anyone in your business tell which lines are basic hygiene you should already have and which are genuinely optional?
When an email asks to change bank details, from a vendor, a customer, or your own leadership, what is the step that happens off email before anyone acts? Is it written down?
If your legitimate email started landing in customers' spam folders tomorrow, how long before you would notice, and who would you call?
Do you carry cyber insurance? If a customer wired money because of an email that came from your domain, who defends that claim?
Is your firewall a business-grade device that someone monitors, or a box from a big-box store that has been blinking in a closet for six years?
Frequently asked
What is the You Can't Reset a Reputation case study about?
A commercial mechanical contractor was never broken into and never had a dollar stolen from its accounts. A phished field-tech password, a domain anyone could forge, and an IT vendor who sold configuration as though it were a product turned the company's own email into a weapon against its customers, its suppliers, its bank, and its attorney. The abuse kept going after every password was changed. The controls that would have stopped it were almost all free. Nobody was there to say so.
Is Ironwood Mechanical a real company?
No. Ironwood Mechanical is a fictional company used to illustrate a real attack pattern. The tactics, techniques, and procedures are real and documented; the company, the people, and the specific details are invented.
What would have prevented this?
The case study breaks down what was missing — across people, process, and technology — and the specific compensating controls that would have stopped the attack, including one action to take this week.