Cyber Incident Briefs

Risk Strategies’ January 2026 Microsoft 365 Account Incident: Data Exposure, Unknowns, and Control Lessons

Risk Strategies reported unauthorized access to a Microsoft 365 account belonging to one of its employees. The public notice says the access occurred over January 15 and 16, 2026, and involved certain emails and files. The organization’s review later confirmed that at least some of that material contained personal information.

The incident is a useful reminder that a Microsoft 365 account is not only an email identity. Depending on permissions and work practices, it can be a route to messages, attachments, OneDrive files, SharePoint content, Teams data, and business relationships. This analysis separates what Risk Strategies reported from what the public record does not establish, then translates the event into practical controls for business and IT leaders.

Executive summary

According to a Risk Strategies notice filed with the Nebraska Attorney General, the organization identified unauthorized access to an employee’s Microsoft 365 account. Its investigation found that certain emails and files were accessed between January 15 and 16, 2026. On June 1, 2026, the review confirmed that one or more of those items contained personal information.

The notice says the information included names and Social Security numbers. For some individuals, it also included medical information and health, dental, or vision insurance information. The Nebraska filing reports 76 Nebraska residents; a separate Indiana breach report lists 15,055 affected individuals nationally. Risk Strategies mailed notices on June 23, 2026.

The public materials reviewed for this analysis do not identify:

  • the initial access method;
  • whether a password, session token, application consent, recovery process, or another identity mechanism was involved;
  • whether multifactor authentication was enabled or bypassed;
  • the identity or motive of the unauthorized party;
  • whether information was downloaded, forwarded, altered, or misused;
  • the employee’s role or the complete set of Microsoft 365 services reachable through the account; or
  • a direct operational or financial loss to Risk Strategies or its customers.

Those points should not be inferred from the fact that a Microsoft 365 account was accessed.

Confirmed incident snapshot

Field Publicly reported information
Organization RSC Insurance Brokerage, Inc., operating as Risk Strategies
Business context Insurance brokerage, consulting, and risk advisory services
Unauthorized-access window January 15–16, 2026
Environment One employee Microsoft 365 account
Material reviewed Certain emails and files
Review milestone June 1, 2026
Notification date June 23, 2026
Information involved Names and Social Security numbers; for some people, medical information and health, dental, or vision insurance information
Reported national count 15,055 in the Indiana Attorney General’s year-to-date breach report
Entry vector Not publicly stated
Threat actor Not publicly identified
Misuse Not established in the cited public notices
Status Account access ended; notices issued; additional security strengthening reported

The table summarizes the cited notices and regulator records. It is not an independent forensic finding.

What happened and when

January 15–16: access to an employee account

Risk Strategies reported that an unauthorized person accessed an employee’s Microsoft 365 account during a two-day period. The notice says certain emails and files were within the accessed material.

The wording matters. The public notice confirms unauthorized account access and the presence of sensitive information in at least some reviewed content. It does not say every message or file in the account was opened, copied, or taken. It also does not say the entire Microsoft 365 tenant was compromised.

Investigation and content review

An account-level incident often creates two separate investigation questions:

  1. What activity did the unauthorized user perform? This requires sign-in, audit, message-trace, mailbox, application, and file-access evidence.
  2. What sensitive information was within the potential scope? This can require a legal and forensic review of messages, attachments, and connected files.

Risk Strategies’ notice says its review of the affected emails and files concluded on June 1, when it confirmed that one or more contained personal information. The several-month interval between the access window and the review milestone illustrates why cloud-email incidents can create substantial notification and investigation work even when the access period itself is short.

June 23: individual notices

Risk Strategies reported mailing notification letters on June 23. The Nebraska filing says the organization offered notified residents complimentary credit monitoring and identity-theft protection services and established a call center.

An Indiana Attorney General breach report lists 15,055 affected individuals nationally. That figure is useful for scope, but it does not establish that every person had the same data elements involved.

What type of cyber incident was this?

The most supportable classification is unauthorized Microsoft 365 account access with potential exposure of email and file content.

It is also reasonable to classify the event as a cloud-identity and data-exposure incident. The public notice does not provide enough information to classify it as phishing, adversary-in-the-middle token theft, password spraying, malware, business email compromise, OAuth abuse, or help-desk social engineering.

Calling the event “a phishing attack” would be speculation. Phishing is common in cloud-account incidents, but frequency is not evidence of the entry method in this case.

Why the incident matters

A single identity can reach several business processes

A Microsoft 365 user may have access to far more than a mailbox. The account can be connected to OneDrive, SharePoint, Teams, shared mailboxes, distribution lists, customer communications, and line-of-business applications. The business impact depends on the role, permissions, retained content, and activity performed—not only on the number of accounts involved.

Email retention can become breach scope

Messages and attachments often accumulate because they are convenient records of customer service, benefits administration, insurance placement, claims, and personnel activity. That convenience can expand incident scope when sensitive files remain in a mailbox longer than the business or regulatory purpose requires.

Sensitive identifiers create durable risk

Passwords can be changed. Social Security numbers and medical or insurance information cannot be easily replaced. Their presence increases the need for careful notification, identity-protection guidance, and long-term monitoring for misuse, even when public evidence does not show that misuse occurred.

Customer trust depends on evidence

Organizations that hold information supplied by customers need to explain what was accessed, what was not, how scope was determined, and what controls changed. If audit retention is too short or logs are not routinely reviewed, the organization may be unable to answer those questions with confidence.

Confirmed facts and unresolved questions

Publicly confirmed

  • An employee Microsoft 365 account was accessed without authorization.
  • The reported access window was January 15–16, 2026.
  • Certain emails and files were within the accessed material.
  • A later review confirmed that one or more items contained personal information.
  • Names and Social Security numbers were involved; some individuals also had medical or health, dental, or vision insurance information involved.
  • Risk Strategies issued notices and reported strengthening security measures.

Not publicly confirmed

  • How the unauthorized user first obtained access.
  • Whether the attacker possessed a password, token, registered authentication method, session cookie, or application permission.
  • Whether administrative privileges or other accounts were reached.
  • Whether inbox rules, forwarding, delegates, applications, or recovery methods were changed.
  • Whether OneDrive, SharePoint, Teams, or shared mailboxes were accessed beyond the files described.
  • Whether the information was downloaded, distributed, sold, or misused.
  • Whether any fraud, wire loss, operational outage, regulatory penalty, litigation outcome, or reputational measurement resulted.
Insurance brokerage security controls separating email identity, policy files, medical benefits records, audit logs, and incident response evidence
The control review should connect Microsoft 365 identity, mailbox access, cloud-file reach, audit evidence, and sensitive insurance or medical information rather than treating the incident as email alone.

Controls that could reduce similar risk

These controls are defensive lessons, not claims about which controls Risk Strategies did or did not have.

1. Enforce phishing-resistant authentication

Microsoft recommends phishing-resistant methods such as passkeys, FIDO2 security keys, Windows Hello for Business, and certificate-based authentication for stronger protection. A staged rollout should begin with administrators, executives, finance, HR, benefits, insurance, and other users whose accounts hold high-impact data.

Traditional push or code-based MFA is still better than password-only access, but it can remain vulnerable to adversary-in-the-middle phishing, repeated approval prompts, and social engineering. Conditional Access authentication strengths can require stronger methods for sensitive users and applications.

2. Treat session revocation as a containment requirement

A password reset does not answer every token and session risk. Microsoft’s compromised-account guidance recommends revoking active sessions, reviewing authentication methods, checking mailbox rules and forwarding, examining sent and deleted items, and investigating Entra sign-in and audit evidence.

Response procedures should define who can disable an identity, revoke sessions, preserve logs, and validate that access has stopped.

3. Review mailbox, OneDrive, SharePoint, and application scope together

Investigators should not assume a mailbox is the only affected workload. Review:

  • Exchange Online audit events, message trace, inbox rules, delegates, and forwarding;
  • Entra sign-ins, risky-user detections, device details, authentication methods, and Conditional Access results;
  • OAuth and enterprise-application consent;
  • OneDrive and SharePoint file-access events and external sharing;
  • Teams activity where the account had access; and
  • connected third-party applications and service accounts.

4. Reduce sensitive data retained in email

Sensitive insurance, medical, benefits, and identity records should use approved systems with appropriate access, retention, and audit controls. Email should not become an indefinite document repository.

Microsoft Purview retention, data-loss prevention, sensitivity labeling, and information-governance capabilities can help, but they need to match business processes, licensing, regulatory duties, and legal-hold requirements. Deleting information without a defensible policy can create a different risk.

5. Preserve enough logs to investigate later

The required retention period depends on licensing, contractual obligations, regulatory requirements, insurance expectations, and the organization’s risk profile. Teams should verify that the audit data they expect to use actually exists, is retained long enough, and can be exported during an incident.

CISA’s Secure Cloud Business Applications resources provide Microsoft 365 configuration baselines covering Entra ID, Exchange Online, Defender for Office 365, OneDrive, SharePoint, Teams, and other services. Although developed for federal use, CISA recommends that other organizations review and apply appropriate practices.

What business and IT leaders should review next

Ask for evidence—not only assurance—on these questions:

  1. Which users can access Social Security numbers, medical information, insurance data, and customer-provided files through Microsoft 365?
  2. Which of those users are required to use phishing-resistant authentication?
  3. Can administrators identify and revoke every active session for a compromised account?
  4. Are suspicious inbox rules, forwarding, delegate changes, and OAuth grants alerted and reviewed?
  5. How long are Entra, Exchange, Purview, SharePoint, and OneDrive audit records retained?
  6. Does the incident plan cover mailbox content review, notification analysis, customer coordination, legal review, cyber-insurance notice, and correction of public statements?
  7. Are sensitive records stored in the right system, or are they accumulating in email and personal OneDrive folders?

OC Security Audit’s Microsoft Office 365 security audit reviews Entra ID, MFA, Conditional Access, Exchange Online, Defender for Office 365, Purview, DLP, sharing, logging, and administrative access. A focused Microsoft 365 email security review can examine phishing protection, authentication, mail flow, forwarding, and mailbox controls. For a broader identity and infrastructure view, see the Azure cloud security audit and the cloud and identity compromise guidance.

Sources

Turn the lesson into a Microsoft 365 control review

If your organization handles insurance, benefits, health, financial, or employee information in Microsoft 365, review identity controls and data scope before an incident forces the question. Contact OC Security Audit to discuss an independent Microsoft 365 security assessment, or learn more about Ali Hassani, CISO and his experience across security, cloud, infrastructure, audit, and incident readiness.

Update and correction history

  • July 2026: Initial analysis prepared from regulator-hosted notices and official Microsoft and CISA guidance.