sensorzero
Sign in Start free
Why SensorZero

Someone can be in your email for three weeks before anything looks wrong.

They do not break anything. They read your invoices, learn how you get paid, and wait for the right one. SensorZero is the part that notices on day one, instead of the day the money leaves.

Start free See how it actually happens
NO HARDWARE · LIVE IN TEN MINUTES · START FREE
Payment redirection · Australia
$166.8m

Lost by Australians to payment redirection in 2025, also known as business email compromise. It is the second-largest scam type by loss in the country, and one of the only ones still rising.

Almost none of it involved breaking through anything. It involved a correct password, typed into a real login page, on a normal Tuesday.

Source: ACCC National Anti-Scam Centre, Targeting scams 2025, published March 2026.

Start where the attack starts

Protect Microsoft 365 and Google Workspace.

SensorZero watches for the sign-in, not the invoice. Connect your email and it reads the activity around your mailboxes from the moment it is on.

Microsoft 365 Google Workspace
SIMPLE CONNECTION · UNDER 10 MINUTES · FIXED COST
Five questions

Would you find out?

Nothing is sent anywhere and no email is required. Answer honestly. Most businesses we speak to answer no to at least three.

01 If someone signed into your email from overseas tomorrow morning, would anyone find out?
02 Do you know what ran on your staff computers last Tuesday?
03 If a staff password was already for sale, would anything tell you?
04 Who in the business reads the security warnings from Microsoft 365 or Google Workspace?
05 If money left on a fake invoice, how long before you noticed?
Your answers

Answer the five above and we will tell you what they add up to.

What actually happens

Nobody breaks in. They log in, and then they wait.

Nobody sat down and picked your business. Sign-in details get harvested in bulk and sorted afterwards, and a ten-person firm that pays invoices is worth exactly as much as a large one. What follows is one real pattern, in the order it happens.

BEFORE DAY 1

They get hold of a password

There are three common ways yours ends up in the pile. None of them require anyone to target you.

A login page that is not yours

An email points at a page that looks exactly like the Microsoft or Google sign-in. Your staff member types the password and approves the prompt on their phone, and it all works, because the fake page is passing it straight through to the real one and keeping the answer. This is why having multi-factor turned on does not settle the question on its own.

Malware from a download or attachment

A malicious download, an email attachment, or a fake software update installs malware that quietly reads every saved password and signed-in session out of the browser and sends them back. It is sold as a subscription service, so whoever uses it does not need to be technical.

A password someone else already had

Credentials are bought and sold on the basis of what the business is, where it is, and roughly what it earns. Sometimes they came from an old breach on an unrelated site where the same password was used again.

DAY 1

They sign in, and it looks completely normal

They are not breaking in. They are logging in, with a correct password and a session your provider has already approved. To Microsoft 365 or Google Workspace it is your bookkeeper starting the day, so nothing is flagged and nobody is told.

SIGN-IN ACTIVITY · MICROSOFT 365 accounts@yourcompany.com.au
Tue 08:14  ·  Melbourne, AU  ·  Windows / Edge success
Tue 08:41  ·  Lagos, NG  ·  Windows / Chrome success
Both succeeded. Both passed multi-factor. Neither generated a warning to anyone in the business.
DAYS 2–22

Nothing happens. That is the attack.

They read. They do not delete anything, change anything, or lock you out, because that would give them away. They are learning how your business asks to be paid: who approves what, when you invoice, which client owes the most, how you sign off.

The one thing they do change is small enough that nobody sees it.

INBOX RULE CREATED  ·  TUE 08:52
name.
if subjectcontains “invoice”, “payment”, “remittance”, “bank”
thenmark as read → move to RSS Subscriptions
A rule named with a single full stop, so it is almost invisible in the list. Anything a client sends about payment is now read and filed away before your bookkeeper sees it.
DAY 23

Your client gets an invoice from you

Right thread, right amount, right sign-off, because they copied a real one. One line is different. Your client pays it, and the money is gone that afternoon.

WHAT YOU SENT
INVOICE 4471 · $38,420.00
Your Company Pty Ltd
BSB  •••-•••
ACC  ••• ••• 712
WHAT YOUR CLIENT RECEIVED
INVOICE 4471 · $38,420.00
Your Company Pty Ltd
BSB  •••-•••
ACC  ••• ••• 233

You find out three weeks later, when the client asks why the account is overdue.

Every alarm you already have is pointed at Day 23. SensorZero is pointed at Day 1.

What day 1 looks like with us

You get an email you can actually act on.

SensorZero correlates sign-ins, mailbox rules and what happens on your computers. When something matters, it does not sit in a console nobody opens. An AI agent triages it and escalates to you in plain English, with what it saw and exactly what to do next.

01Two sign-ins that cannot both be true get caught the morning they happen.
02A new rule that hides invoice emails is not a normal thing for a bookkeeper to create.
03A case is opened and the evidence is gathered before you have finished reading.
Tue 09:03  ·  to: you@yourcompany.com.au
sensorzero
ALERT ESCALATED

An alert needs your attention

HIGH

Our monitoring has flagged a high-severity impossible-travel event on one of your accounts, and a case has been opened.

What this means

The account accounts@yourcompany.com.au signed into Microsoft 365 from Melbourne and from Lagos within 27 minutes. That is not possible, and it usually means the password is being used by someone else. A new inbox rule was created from the second session.

What to do next

Check whether that staff member was travelling. If not, revoke the active sessions, reset the password and delete the rule. The steps are in the case.

Open the case This was expected
How SensorZero helps

Three places to look, and one place it all lands.

SensorZero collects the activity from your email, your computers and your network in one place, and checks it as it arrives. Who signed in, from where, and what they changed once they were in.

Cloud & SaaS

Microsoft 365, Google Workspace

Sign-ins, locations, mailbox rules, permission changes, file sharing. This is where payment redirection starts and ends.

Endpoint sensor

Laptops, desktops, servers

One lightweight agent per machine. What ran, what it touched, and whether it went looking for saved passwords.

Network sensor

Passive traffic

Where your network is talking to, including the things a laptop cannot tell you about itself.

sensorzero
The usual questions

Fair questions, answered plainly.

“We are too small to be worth it.”

Small businesses are viable targets, and some lose between $50,000 and $400,000 or more before they realise an incident has happened at all. Phishing emails and credential stealers are aimed at companies of every size.

“We already have antivirus and multi-factor.”

Keep them, but they do not see or prevent everything. Multi-factor can be bypassed by a fake login page that passes your details straight through to the real one, and your antivirus will not catch that either.

“We have no one to run it.”

You have us. Connect your systems and logs, and our AI SOC triages and escalates the alerts that matter to you. You can also partner with an MSP to run it alongside you, and the SensorZero team performs hunts and escalates ad-hoc findings.

“We cannot commit budget to this.”

Start free. SensorZero fixed plans then make the cost predictable, so you know what you are paying, with no capex and no year-one lock-in.

“We would not know what to do with an alert.”

You get the email above: what happened, why it matters, and the exact steps to take. It is written in plain English, not console output.

“Who is actually behind this?”

A team of experienced incident response and digital forensics engineers, who have worked large scale incidents for large and small companies. SensorZero is that experience, productised.

A PRODUCT BY EVIANT

Built by an experienced team.

SensorZero is actively developed and maintained by a team of experienced incident response and digital forensics engineers. The team have worked large scale incidents and detected advanced persistent threat activity for large companies and small companies.

Find out what is already happening in your email.

Connect Microsoft 365 or Google Workspace and detection runs from the moment it is on. Ten minutes, no hardware, free to start.

Start free Explore the platform