Home»Time Entries Audit loading ... generated 8/7/2026 at 4:35:46 pm took 0.42 seconds version: 5436fa4 helpers: v2

Territory: BMS Dates: 7/1/26 to 7/31/26 Company: IC [x] Ticket: all User: all Type: all Role: all Bill: all Timesheet:  6/29 7/6 7/13 7/20 7/27  [x] Board: all Entry Status: ReadyToBill [x] Ticket Status: all Issue: all [reset] Progress: 100% (2 of 2)

row id Terr Company User Date Day Start End Actual Billed Deduct Inv Amt Work Type Work Role Bill Timesheet Board Entry Status Ticket Status Ticket # Ticket Summary Int Notes Audit Done Audit Notes Notes # issues all issues errors warnings notices
1 42161 BMS IC fdrewett 7/3 9:30 am 10:30 am 1.00 1.00 0 125.00 Remote Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 1 8/6 CS long notes ok Security incident response - Microsoft 365 account \(Kole Spathelf\) On July 3, our monitoring partner detected that an outside party had signed into Kole Spathelf's Microsoft 365 account from an unauthorized location. The account did not have multi-factor authentication turned on, which allowed the sign-in using only the password. The account was automatically locked down within about 11 minutes of detection, cutting off the intruder's access. We then performed a full investigation and confirmed the intruder did not set up any hidden access, forwarding, or other means to get back in. During the brief access window, the intruder viewed roughly 110 emails, mostly routine company announcements and pay notifications. There was no evidence that any email was sent, moved, or deleted from the account. To secure the account, we reset the password and turned on multi-factor authentication, which will prompt Kole to set up a second verification step at next sign-in. The account has been safely returned to normal use. Recommended next step: we advise enabling multi-factor authentication across all user accounts in your Microsoft 365 environment to prevent this type of intrusion going forward. We're happy to schedule this with you. 1 Notices: Notes: Notes longer than 500 characters Notes: Notes longer than 500 characters
2 42162 BMS IC fdrewett 7/3 10:45 am 11:45 am 1.00 1.00 0 125.00 Remote Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 1 8/6 CS long notes ok Security incident response and account decommission, Microsoft 365 account \(Dijon White\) On July 3, our monitoring partner detected that an outside party had gained access to Dijon White's Microsoft 365 account from an unauthorized location, using a stolen sign-in session. This was the second such attempt against your organization that day from the same source. The account was automatically locked down within about 6 minutes of detection, cutting off the intruder's access. We then performed a full investigation and confirmed the intruder did not set up any hidden access, forwarding, or other means to get back in. Because this account belonged to an employee whose last day was July 2, and at your direction, we converted the mailbox to an archive-only mailbox \(retaining the email for your records\), blocked all sign-in to the account, and removed its paid license to free up the subscription seat. Recommended next step: we advise enabling multi-factor authentication across all user accounts and reviewing sign-in protections for your Microsoft 365 environment, as your organization was targeted twice in one day. We're happy to schedule this with you. 1 Notices: Notes: Notes longer than 500 characters Notes: Notes longer than 500 characters
3 42151 BMS IC ggonzales 7/2 10:38 am 1:53 pm 3.25 3.25 0 406.25 Remote Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 0 Steps taken: * Investigating incedent * Found and adjusted various accounts noted internally * Called clients and assisted with getting them back into after confirming everything was clean Next Steps: * Continue assisting with cleanup 0
4 42377 BMS IC rclingan 7/2 11:25 am 11:30 am 0.08 1.00 0 25.00 Travel Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 0 travel for onsite visit to deal with initial security incidents 0
5 42378 BMS IC rclingan 7/2 11:30 am 11:48 am 0.30 1.00 0 125.00 Onsite Standard Technician Billable 6/29 Help Desk 2.1 ReadyToBill -Closed 78900 Fraud Email 0 remediated accounts with courtney and provided updated information to be given to users. 0

Legend:
(hover over fields for details)

Error (0)
Warning (0)
Notice (2)


Tickets with over 5 hours in the current view (1)

Hours Ticket # Company Ticket Summary
6.25 78900 IC Fraud Email


Notices

Field Message Count
Notes  Notes longer than 500 characters  2
Total  2


42161 - fdrewett - 7/3 9:30 am - 78900 - Fraud Email
Notes longer than 500 characters

42162 - fdrewett - 7/3 10:45 am - 78900 - Fraud Email
Notes longer than 500 characters