Cyber Incident Briefs
Risk Strategies’ January 2026 Microsoft 365 Account Incident: Data Exposure, Unknowns, and Control Lessons

Risk Strategies reported unauthorized access to a Microsoft 365 account belonging to one of its employees. The public notice says the access occurred over January 15 and 16, 2026, and involved certain emails and files. The organization’s review later confirmed that at least some of that material contained personal information.
The incident is a useful reminder that a Microsoft 365 account is not only an email identity. Depending on permissions and work practices, it can be a route to messages, attachments, OneDrive files, SharePoint content, Teams data, and business relationships. This analysis separates what Risk Strategies reported from what the public record does not establish, then translates the event into practical controls for business and IT leaders.
Executive summary
According to a Risk Strategies notice filed with the Nebraska Attorney General, the organization identified unauthorized access to an employee’s Microsoft 365 account. Its investigation found that certain emails and files were accessed between January 15 and 16, 2026. On June 1, 2026, the review confirmed that one or more of those items contained personal information.
The notice says the information included names and Social Security numbers. For some individuals, it also included medical information and health, dental, or vision insurance information. The Nebraska filing reports 76 Nebraska residents; a separate Indiana breach report lists 15,055 affected individuals nationally. Risk Strategies mailed notices on June 23, 2026.
The public materials reviewed for this analysis do not identify:
- the initial access method;
- whether a password, session token, application consent, recovery process, or another identity mechanism was involved;
- whether multifactor authentication was enabled or bypassed;
- the identity or motive of the unauthorized party;
- whether information was downloaded, forwarded, altered, or misused;
- the employee’s role or the complete set of Microsoft 365 services reachable through the account; or
- a direct operational or financial loss to Risk Strategies or its customers.
Those points should not be inferred from the fact that a Microsoft 365 account was accessed.
Confirmed incident snapshot
| Field | Publicly reported information |
|---|---|
| Organization | RSC Insurance Brokerage, Inc., operating as Risk Strategies |
| Business context | Insurance brokerage, consulting, and risk advisory services |
| Unauthorized-access window | January 15–16, 2026 |
| Environment | One employee Microsoft 365 account |
| Material reviewed | Certain emails and files |
| Review milestone | June 1, 2026 |
| Notification date | June 23, 2026 |
| Information involved | Names and Social Security numbers; for some people, medical information and health, dental, or vision insurance information |
| Reported national count | 15,055 in the Indiana Attorney General’s year-to-date breach report |
| Entry vector | Not publicly stated |
| Threat actor | Not publicly identified |
| Misuse | Not established in the cited public notices |
| Status | Account access ended; notices issued; additional security strengthening reported |
The table summarizes the cited notices and regulator records. It is not an independent forensic finding.
What happened and when
January 15–16: access to an employee account
Risk Strategies reported that an unauthorized person accessed an employee’s Microsoft 365 account during a two-day period. The notice says certain emails and files were within the accessed material.
The wording matters. The public notice confirms unauthorized account access and the presence of sensitive information in at least some reviewed content. It does not say every message or file in the account was opened, copied, or taken. It also does not say the entire Microsoft 365 tenant was compromised.
Investigation and content review
An account-level incident often creates two separate investigation questions:
- What activity did the unauthorized user perform? This requires sign-in, audit, message-trace, mailbox, application, and file-access evidence.
- What sensitive information was within the potential scope? This can require a legal and forensic review of messages, attachments, and connected files.
Risk Strategies’ notice says its review of the affected emails and files concluded on June 1, when it confirmed that one or more contained personal information. The several-month interval between the access window and the review milestone illustrates why cloud-email incidents can create substantial notification and investigation work even when the access period itself is short.
June 23: individual notices
Risk Strategies reported mailing notification letters on June 23. The Nebraska filing says the organization offered notified residents complimentary credit monitoring and identity-theft protection services and established a call center.
An Indiana Attorney General breach report lists 15,055 affected individuals nationally. That figure is useful for scope, but it does not establish that every person had the same data elements involved.
What type of cyber incident was this?
The most supportable classification is unauthorized Microsoft 365 account access with potential exposure of email and file content.
It is also reasonable to classify the event as a cloud-identity and data-exposure incident. The public notice does not provide enough information to classify it as phishing, adversary-in-the-middle token theft, password spraying, malware, business email compromise, OAuth abuse, or help-desk social engineering.
Calling the event “a phishing attack” would be speculation. Phishing is common in cloud-account incidents, but frequency is not evidence of the entry method in this case.
Why the incident matters
A single identity can reach several business processes
A Microsoft 365 user may have access to far more than a mailbox. The account can be connected to OneDrive, SharePoint, Teams, shared mailboxes, distribution lists, customer communications, and line-of-business applications. The business impact depends on the role, permissions, retained content, and activity performed—not only on the number of accounts involved.
Email retention can become breach scope
Messages and attachments often accumulate because they are convenient records of customer service, benefits administration, insurance placement, claims, and personnel activity. That convenience can expand incident scope when sensitive files remain in a mailbox longer than the business or regulatory purpose requires.
Sensitive identifiers create durable risk
Passwords can be changed. Social Security numbers and medical or insurance information cannot be easily replaced. Their presence increases the need for careful notification, identity-protection guidance, and long-term monitoring for misuse, even when public evidence does not show that misuse occurred.
Customer trust depends on evidence
Organizations that hold information supplied by customers need to explain what was accessed, what was not, how scope was determined, and what controls changed. If audit retention is too short or logs are not routinely reviewed, the organization may be unable to answer those questions with confidence.
Confirmed facts and unresolved questions
Publicly confirmed
- An employee Microsoft 365 account was accessed without authorization.
- The reported access window was January 15–16, 2026.
- Certain emails and files were within the accessed material.
- A later review confirmed that one or more items contained personal information.
- Names and Social Security numbers were involved; some individuals also had medical or health, dental, or vision insurance information involved.
- Risk Strategies issued notices and reported strengthening security measures.
Not publicly confirmed
- How the unauthorized user first obtained access.
- Whether the attacker possessed a password, token, registered authentication method, session cookie, or application permission.
- Whether administrative privileges or other accounts were reached.
- Whether inbox rules, forwarding, delegates, applications, or recovery methods were changed.
- Whether OneDrive, SharePoint, Teams, or shared mailboxes were accessed beyond the files described.
- Whether the information was downloaded, distributed, sold, or misused.
- Whether any fraud, wire loss, operational outage, regulatory penalty, litigation outcome, or reputational measurement resulted.

Controls that could reduce similar risk
These controls are defensive lessons, not claims about which controls Risk Strategies did or did not have.
1. Enforce phishing-resistant authentication
Microsoft recommends phishing-resistant methods such as passkeys, FIDO2 security keys, Windows Hello for Business, and certificate-based authentication for stronger protection. A staged rollout should begin with administrators, executives, finance, HR, benefits, insurance, and other users whose accounts hold high-impact data.
Traditional push or code-based MFA is still better than password-only access, but it can remain vulnerable to adversary-in-the-middle phishing, repeated approval prompts, and social engineering. Conditional Access authentication strengths can require stronger methods for sensitive users and applications.
2. Treat session revocation as a containment requirement
A password reset does not answer every token and session risk. Microsoft’s compromised-account guidance recommends revoking active sessions, reviewing authentication methods, checking mailbox rules and forwarding, examining sent and deleted items, and investigating Entra sign-in and audit evidence.
Response procedures should define who can disable an identity, revoke sessions, preserve logs, and validate that access has stopped.
3. Review mailbox, OneDrive, SharePoint, and application scope together
Investigators should not assume a mailbox is the only affected workload. Review:
- Exchange Online audit events, message trace, inbox rules, delegates, and forwarding;
- Entra sign-ins, risky-user detections, device details, authentication methods, and Conditional Access results;
- OAuth and enterprise-application consent;
- OneDrive and SharePoint file-access events and external sharing;
- Teams activity where the account had access; and
- connected third-party applications and service accounts.
4. Reduce sensitive data retained in email
Sensitive insurance, medical, benefits, and identity records should use approved systems with appropriate access, retention, and audit controls. Email should not become an indefinite document repository.
Microsoft Purview retention, data-loss prevention, sensitivity labeling, and information-governance capabilities can help, but they need to match business processes, licensing, regulatory duties, and legal-hold requirements. Deleting information without a defensible policy can create a different risk.
5. Preserve enough logs to investigate later
The required retention period depends on licensing, contractual obligations, regulatory requirements, insurance expectations, and the organization’s risk profile. Teams should verify that the audit data they expect to use actually exists, is retained long enough, and can be exported during an incident.
CISA’s Secure Cloud Business Applications resources provide Microsoft 365 configuration baselines covering Entra ID, Exchange Online, Defender for Office 365, OneDrive, SharePoint, Teams, and other services. Although developed for federal use, CISA recommends that other organizations review and apply appropriate practices.
What business and IT leaders should review next
Ask for evidence—not only assurance—on these questions:
- Which users can access Social Security numbers, medical information, insurance data, and customer-provided files through Microsoft 365?
- Which of those users are required to use phishing-resistant authentication?
- Can administrators identify and revoke every active session for a compromised account?
- Are suspicious inbox rules, forwarding, delegate changes, and OAuth grants alerted and reviewed?
- How long are Entra, Exchange, Purview, SharePoint, and OneDrive audit records retained?
- Does the incident plan cover mailbox content review, notification analysis, customer coordination, legal review, cyber-insurance notice, and correction of public statements?
- Are sensitive records stored in the right system, or are they accumulating in email and personal OneDrive folders?
OC Security Audit’s Microsoft Office 365 security audit reviews Entra ID, MFA, Conditional Access, Exchange Online, Defender for Office 365, Purview, DLP, sharing, logging, and administrative access. A focused Microsoft 365 email security review can examine phishing protection, authentication, mail flow, forwarding, and mailbox controls. For a broader identity and infrastructure view, see the Azure cloud security audit and the cloud and identity compromise guidance.
Sources
- Risk Strategies notice and Nebraska Attorney General filing, June 2026
- Indiana Attorney General year-to-date breach report, July 2026
- Massachusetts data-breach notification record for RSC Insurance Brokerage, Inc.
- Microsoft: Respond to a compromised cloud email account
- Microsoft: Plan a phishing-resistant passwordless authentication deployment
- CISA: Microsoft 365 Secure Configuration Baselines
Turn the lesson into a Microsoft 365 control review
If your organization handles insurance, benefits, health, financial, or employee information in Microsoft 365, review identity controls and data scope before an incident forces the question. Contact OC Security Audit to discuss an independent Microsoft 365 security assessment, or learn more about Ali Hassani, CISO and his experience across security, cloud, infrastructure, audit, and incident readiness.
Compare this incident with the STRATeBEN phishing analysis and the Conifer healthcare email incident, then use the first-alert incident-response guide to test investigation, containment, and recovery decisions.
Update and correction history
- July 2026: Initial analysis prepared from regulator-hosted notices and official Microsoft and CISA guidance.