Lack of MFA Is Common Thread in Vast Cloud Credential Heist
ID: 1b0a4557-ddbd-50bb-978d-49bd5eff0724
STIX ID: report--1b0a4557-ddbd-50bb-978d-49bd5eff0724
Feed Name: Dark Reading
Date Published: 2026-01-07
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Hudson Rock reports a campaign by a threat actor called "Zestix/Sentap" who leveraged infostealers (e.g., RedLine, Lumma, Vidar) to harvest saved credentials from infected machines and used those credentials to access enterprise file-sharing/collaboration platforms (ShareFile, OwnCloud, Nextcloud) lacking MFA; stolen data from about 50 firms was being auctioned and thousands more organizations are identified as at risk due to exposed credentials in infostealer logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
