logo

One criminal, 50 hacked organizations, and all because MFA wasn't turned on

ID: 62f0eaed-3321-5777-b042-897598a46036

STIX ID: report--62f0eaed-3321-5777-b042-897598a46036

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-01-06

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Zestix (also known as Sentap) is operating an active infostealer campaign that harvests credentials from infected endpoints (using malware such as RedLine, Lumma, and Vidar) to log into enterprise file synchronization and sharing platforms lacking enforced MFA, exfiltrate sensitive corporate and infrastructure data from around 50 organizations (including engineering, health, aviation, and defense-related files), and sell the stolen datasets on the dark web; the report emphasizes credential hygiene and enforcing MFA as primary mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.