{"type":"video","version":"1.0","html":"<iframe src=\"https://www.loom.com/embed/bc87b131a2024bc4bd3fc0530820dd92\" frameborder=\"0\" width=\"1920\" height=\"1440\" webkitallowfullscreen mozallowfullscreen allowfullscreen></iframe>","height":1440,"width":1920,"provider_name":"Loom","provider_url":"https://www.loom.com","thumbnail_height":1440,"thumbnail_width":1920,"thumbnail_url":"https://cdn.loom.com/sessions/thumbnails/bc87b131a2024bc4bd3fc0530820dd92-d0f17639af731780.gif","duration":224.233,"title":"Understanding Compromised Accounts and Actions","description":"This Loom explains Compromised Account detection, where an attacker takes over a real internal email account and sends phishing or spam from within the legitimate domain. It shows how the Compromised Accounts view lists all flagged accounts in one place, with a sidebar count of accounts currently suspended and waiting for action that updates automatically. Suspended accounts are marked with a red dot and cannot send, while reinstated accounts are marked green, and the app redirects to this page on login if any are suspended. For each account, viewers can review case details such as AI threat score, threat class, reported-by information, evidence signals, and the option to view the original email, then reinstate either case resolved or false positive after securing the account."}