4

High-Risk Users

SL-11

Who is actually being targeted. Repeat encounters matter more than single ones, and a user flagged here who is also flagged by Access Assurance is the pattern that precedes credential misuse escalating into broad data access.

DischargesS.8(4)R.6
Users targeted
18
Repeat targets
18
Correlated with anomalies
0
Privileged users targeted
0
Campaign clustering

Detections grouped by campaign. Several users hitting the same infrastructure within a short window is a targeted campaign rather than opportunistic traffic, and it changes the response.

18 users

Nitin Patel
421Critical10 days ago
Tanvi Chopra
443Critical2 days ago
Rekha Saxena
432Critical4 days ago
Chetan Sharma
431Criticalyesterday
Aarav Rao
4211Critical5 days ago
Rajesh Mehta
4321Criticalyesterday
Rahul Gupta
444Critical8 days ago
Suresh Bhatt
432Critical9 days ago
Ishaan Mishra
43Criticalyesterday
Arjun Desai
4321High5 days ago
Farhan Kaur
31Critical16 days ago
Kiran Iyer
321Critical2 days ago
Simran Chauhan
331Medium9 days ago
Vandana Singh
321Critical2 days ago
Yash Kulkarni
322Critical11 days ago
Anil Ahluwalia
321Critical11 days ago
Manish Saxena
321Highyesterday
Imran Khanna
321Critical27 days ago

What to do with this list

Treat it as a targeting report, not a performance review. People who encounter more phishing are usually the ones whose role makes them worth targeting — finance, HR, privileged administrators. The proportionate responses are step-up authentication for correlated users, and a training campaign built from their own blocked encounters rather than from generic material.