logo

Hundreds Of Network Operators’ Credentials Found Circulating In Dark Web

ID: 04cc4ce8-a594-5a57-bb3b-1bee328f40fe

STIX ID: report--04cc4ce8-a594-5a57-bb3b-1bee328f40fe

Feed Name: infostealers.com

Threat Score
78/100

Date Published: 2024-01-30

Date Updated: 2026-04-28

Author: Alon Gal

...
...

Resecurity details the January 2024 Orange España incident in which an attacker ('Snow') used credentials stolen by infostealer malware to hijack a RIPE NCC account and deliberately misconfigure BGP and RPKI, causing a multi-hour outage; the report also reveals 1,572 compromised registry credentials discovered on the dark web across RIPE, APNIC, AFRINIC and LACNIC, highlights widespread infostealer activity targeting telecom engineers, and urges stronger credential hygiene and mandatory MFA for registry accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.