logo

SIM-Swap to Data Leak on Dark Web (Incident)

ID: 482fb3be-ecae-53bf-a0f8-1c2635b6ce10

STIX ID: report--482fb3be-ecae-53bf-a0f8-1c2635b6ce10

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2023-04-18

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

An adversary used a SIM-swap against an employee to access email and SCM accounts, discovered ten cloud access keys (including one with IAMFullAccess) in the source repository, created privileged users to escalate access, performed reconnaissance and lateral movement, and exfiltrated sensitive data that was later posted on the dark web after extortion was refused; primary failures cited are overly permissive identities, credential leaks in code repositories, and insufficient logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.