logo

When Threat Actors Behave Like Managed Service Providers

ID: bd36068a-5263-550c-afa5-c40bd37bf861

STIX ID: report--bd36068a-5263-550c-afa5-c40bd37bf861

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-05-01

Date Updated: 2026-04-21

Author: Steve Stasiukonis

...
...

This account describes a ransomware attack on a company where the attacker deployed encryption, exfiltrated hundreds of gigabytes of data, and pressured the victim into ransom payment; the response was hampered by the customer's reckless actions (allowing attacker RDP access, refusing credential changes, open firewall rules, no backups or insurance), resulting in extended downtime, data compromise, and reputational damage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.