// ATO

6h to full containment
At 3:14 AM on a Sunday, Kairo's anomaly detection fired. Login volume was 14x normal, coming from 40+ IP ranges. By 3:30 AM, 3,812 customer accounts had been accessed and loyalty points worth $1.8M were being drained in real time.
Credential stuffing is not sophisticated — it is industrial. Attackers buy breach dumps from the dark web, run automated tools against login endpoints, and cash out whatever they find before defenses respond. The attack on Kairo used credentials from a third-party breach announced 9 days earlier. Kairo had been on the affected company's notification list. The email had landed in a shared inbox nobody was actively monitoring.
Kairo operated a retail loyalty platform. Their customers accumulated points over years of purchases — points that had real redemption value as digital gift cards. The attacker's playbook was efficient: log in, check point balance, redeem for the highest-value gift card available, move to next account. At peak, they were completing 40 account takeovers per minute.
The attack started on a Sunday at 3:14 AM — not an accident. Weekend nights have lower SOC staffing and slower escalation paths. The attackers knew this.
| 3:14 AM | Anomaly detection fires: login volume at 820 requests/second, 14x normal baseline. |
| 3:22 AM | On-call engineer escalates to CyberPhoenix emergency line. |
| 3:31 AM | 3,812 accounts confirmed accessed. Gift card redemptions totaling $1.8M in progress. |
| 3:48 AM | Emergency engagement begins. First rate-limiting rules deployed within 12 minutes. |
| 4:19 AM | Bot detection layer active. Attack traffic drops 94%. Legitimate users temporarily affected (22-minute window). |
| 4:41 AM | Rate-limiting tuned. Legitimate traffic restored. Attack traffic holding at ~2%. |
| 5:30 AM | Forced password reset for all 3,812 impacted accounts. Proactive SMS notifications sent. |
| 7:00 AM | Gift card issuer contacted; 67% of redeemed cards successfully frozen before use. |
| 9:14 AM | Full containment confirmed. SIM-swap monitoring deployed. Passkey rollout initiated for high-value accounts. |
The initial bot detection rules were too broad — they blocked legitimate login traffic for 22 minutes, causing customer complaints and a support surge on top of an active incident. The team had to tune the ruleset under live attack conditions, which required careful judgment about which signals were attack-specific vs. shared with legitimate users. Getting that wrong in either direction would have been costly.