For weeks, no one inside the company saw anything unusual. The corporate perimeter had not been touched. The executive's work laptop, work phone, and work email account showed no anomalies because none had occurred. The attackers had not gone near them.
They had gone to the house instead. A targeted phishing attempt against a member of the executive staff had failed, but the failure produced something more valuable than success: confirmation that the staff was the wrong target. The attackers shifted their attention to the principal himself, and to the digital environment surrounding his private life, where there was no security operations team watching.
Through a combination of exposed personal data, compromised browser sessions, and weaknesses inside the home network, they assembled a portrait of his household over the course of three weeks. They did not need to break anything. Most of what they took was already public, or already weakly defended.