How RED5 identified, contained & stopped a phishing threat before it could spread.

At the end of 2025, RED5 Systems identified a phishing campaign targeting multiple organisations across the Isle of Man through compromised legitimate business email accounts. The attack was mainly focused on the construction industry, though it was not limited to it.
The attackers used real business mailboxes to send mass BCC emails to entire contact lists, hoping someone would click. If successful, they would gain access to another account and repeat the process, allowing the threat to spread quickly from one organisation to the next.
RED5 identified the threat early, contained it within minutes, and took proactive action to protect clients before users were even aware there was a problem.
The Challenge
This was not an isolated incident affecting one organisation. It was a wider phishing campaign targeting multiple clients, with an Isle of Man focus but the potential to spread further.
Because the emails came from legitimate accounts that has been compromised, they were more convincing than a typical phishing attempt. That increased the risk of someone engaging with the message and allowing the attack to continue.
The challenge was not only to identify and remove the threat from affected inboxes, but to act quickly enough to stop it spreading to other clients who had not yet been affected.
Our Solution
RED5 became aware of the issue when our monitoring systems quarantined suspicious emails for review. From there, our team investigated the messages in a secure environment to confirm the threat and understand how it worked.
Once identified, we moved quickly to contain and remove the risk. Our response included:
- Sandboxing quarantined emails to assess the threat safely.
- Blocking sender addresses, sender domains, file hashes, and malicious URLs.
- Submit a threat report to Microsoft Analysis team.
- Removing threat emails from inboxes.
- Updating firewall and filtering rules.
- Proactively monitoring sign-in logs for any signs of malicious activity.
- Contacting each client individually to explain the threat and confirm that RED5 was on top of it.
- Extending protective action beyond directly affected clients to help prevent compromise elsewhere, including offshore client environments.
The key containment work happened within minutes, and the full response was completed within one afternoon.
The Outcome
No breach took place. RED5’s defences identified the phishing attempt early, stopped it spreading, and helped protect multiple organisations before the issue could develop into something more serious.
Just as importantly, we did not limit our response to the clients who had already received the emails. We took ownership of the wider risk, applied protections more broadly, and contacted clients before they were even aware there was a threat.
That is the RED5 approach in practice: personal service, proactive support, and technology that protects businesses in the background so they can stay focused on running them.



