SECURITYTHE REGISTER
All the passwords were stored in Active Directory description fields
A company stored service account passwords in Active Directory description fields, leading to a ransomware attack after hackers accessed these credentials via phishing and the Sliver tool. The breach resulted in 2000+ users being affected and the company being offline for months.
Mentioned
Related Signal
Adjacent reporting
- [Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data
- Ultrahuman says hackers accessed customers’ wellness data via internal tool
- FleetWave outage takes another turn. Chevin confirms crooks accessed customer data
- Vercel’s security breach started with malware disguised as Roblox cheats
- Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul
- Foxconn Ransomware Attack Shows Nothing Is Safe Forever