Regular Password Resets Aren’t as Safe as You Think
ID: 463c5fb2-9d1c-57c2-aefa-eb4a9a8801bb
STIX ID: report--463c5fb2-9d1c-57c2-aefa-eb4a9a8801bb
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** The report recounts an April 2025 attack on Marks & Spencer in which attackers linked to Scattered Spider used a social-engineered password reset via a third‑party service desk to obtain credentials, extract Active Directory NTDS.dit, crack hashes, escalate privileges, and deploy ransomware that disrupted online sales for five days; it promotes Specops Secure Service Desk and outlines best practices for hardening password reset processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
