I received an email to take a look at a file called Evaluation.xFile. Now normally I would ignore it and send it to the trash but the site that the file was being hosted on was sharepoint.com which is supposed to be a safe site and the contact was someone I knew. Unfortunately, that sender’s account (and mine could have been too if it had a keylogger) was compromised so basically, you had a rogue file on a safe site.
This is why VPN can be dangerous and instead, you should have the employee provide their home’s IP address so that it can be added to the allowed list to get behind the network firewall so if their account gets compromised, the most that will happen is a bunch of emails being sent out and you can have a dummy email account that if it gets mail from the attacker sending to everyone in the address book, alert to the intrusion.