Leaked passwords and missing MFA gave an attacker access to cloud tenants
Hudson Rock has examined an actor operating as Zestix and Sentap that gained access to cloud environments at several large organisations. The access came from passwords harvested from infected client machines over time. That old passwords still worked suggests the organisations neither rotated credentials nor monitored for their own leaked ones. The abused accounts also had no multi-factor authentication.
What this means for your organisation
This is not an advanced attack. It is a valid login. Monitoring that looks for intrusions will not react, and data extraction resembles normal use. One infected personal machine plus a cloud account without MFA is enough for large volumes of data to leave. It is a compliance question too: missing MFA on administrative accounts is hard to defend in front of a regulator.
Berigo recommends
- Map which accounts can still sign in without multi-factor authentication, and close them this month.
- Set up continuous monitoring for leaked credentials tied to your domains.
- Require MFA and device compliance for all cloud access, including service accounts and consultants.
- Alert on logins from unusual locations and on abnormal download volumes.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch