Cover art for the blog titled "Who Reads Your 2 a.m. Alert?" by D3 Security

Who Reads Your 2 a.m. Alert?

On Saturday, 28 June 2025, someone called an agent at a third-party contact centre working for Qantas, posed as Qantas IT support, and talked the agent into authorizing access to a data extraction tool. The CRM platform generated login-attempt alerts that day. A Qantas staff member identified them on the morning of Monday, 30 June, and Qantas revoked the account’s access the same day. About 5.67 million customer records were compromised, according to the Australian privacy regulator’s report, published in July 2026.

The regulator called Qantas’s response prompt, and containment came the same day the alerts were spotted. The alerts themselves fired on a Saturday and were identified on a Monday.

Call it the 2 a.m. problem. The alert fires, and the person who can read it is asleep.

The attacker’s clock keeps running

In April, Microsoft published its analysis of an AI-enabled device-code phishing campaign. In some cases, the attackers registered a new device for long-term access within 10 minutes of compromising an account. In others, they waited several hours before creating inbox rules or taking email, to avoid immediate detection.

Ransomware timelines are measured in days. Sophos researchers analyzed 15 Gentlemen ransomware intrusions. In the ones where dwell time could be measured, the median time from first post-compromise activity to ransomware deployment was about two days, and the shortest was under 24 hours. An alert raised on a Saturday and read on Monday morning can be read after the ransomware is deployed.

Who reads the 2 a.m. alert today

The usual answers are a night shift, an on-call rotation, or an MDR provider’s analysts. In all three, a person reads the alert to decide whether it matters. A paging rule only knows what it was written to check. To a rule, an impossible-travel login from a new VPN exit node can look the same as one from an attacker, so it wakes someone for both or sleeps through both.

An agentic alert triage platform should do that first read.

What Morpheus does at 2 a.m.

Morpheus is the accountable agentic SOC platform. It investigates every alert around the clock and pages your on-call only when a finding is graded and worth waking someone for, with the evidence and a drafted response attached.

Say an impossible-travel alert fires on a service account at 2:40 a.m. Morpheus correlates the login against the endpoint, the VPN log and the account’s 90-day history. If the login traces to a known VPN exit, the verdict is benign, the evidence goes on the record, and nobody is woken. If the evidence confirms a compromise, the on-call lead gets paged with containment drafted.

Every finding is graded by its evidence: Confirmed (source telemetry attached), Inferred (reasoning shown, evidence circumstantial) or Gap (Morpheus looked, found nothing, and says so). Up to 95% of alerts reach a graded verdict in under two minutes, per customer-reported production data. When Morpheus is uncertain, it defers to a human.

Benign verdicts get the same record as the ones that page someone, so the morning review is a read, not a reconstruction. The 800+ integrations underneath are self-healing: Morpheus detects API drift, typically within minutes of a vendor pushing an update, and generates the fix.

Decide what runs while you sleep

Morpheus runs in four autonomy modes: Deterministic, AI-Assisted, AI-Led, and Autonomous, set per alert type. An AI-Led alert type gets its response drafted and waiting for sign-off. An Autonomous type runs inside gates you set at design time, and any action can be rolled back. Each incident keeps one audit trail that produces evidence for your auditors.

The queue gets quieter. Control stays where your governance requires it. The AI is included in the subscription.

Noise Down, Security Up.

See it on October 21

On Wednesday, October 21, from 10:00 to 11:00 a.m. PDT, D3 is running a live session: How to Run a 24/7 SOC with AI, Without Waking Up to a Mess. It covers taking L1 and L2 investigation off your analysts around the clock, verifying a verdict without reconstructing the investigation, and where escalation to a human belongs. Register for the session.

Learn More About Morpheus

Powering the World’s Best SecOps Teams

Ready to see Morpheus?