Root cause

The route an attacker used is not the reason the incident succeeded.

A phishing email is how they got in. It does not explain why one click reached the domain administrator account, why nobody noticed for six weeks, or why the backups were deletable. Stopping the analysis at the initial access produces a fix for one email and leaves everything that turned it into a crisis exactly as it was. The useful question is not how they got in, it is why that was enough.

Checked against the primary source.

More on Incident response