logo

Lessons learned from a Man-in-the-Middle attack

ID: eda980e2-1d0c-5d85-b7d3-daa3a3530500

STIX ID: report--eda980e2-1d0c-5d85-b7d3-daa3a3530500

Feed Name: Fox-IT blog

Threat Score
50/100

Date Published: 2017-12-14

Date Updated: 2026-04-27

Author: Fox It

...
...

Fox-IT reports a September 19, 2017 incident in which an attacker obtained access to their third-party domain registrar account, modified DNS records and deployed a fraudulent SSL certificate to perform a Man-in-the-Middle attack against their ClientPortal and briefly redirect email; the attacker intercepted 12 file transfers (10 unique), credentials for nine users (2FA prevented misuse), and some user metadata. The incident was detected and contained within ~10 hours, law enforcement was engaged, affected parties notified, and Fox-IT published remediation steps and recommendations (use of 2FA at registrars, certificate transparency monitoring, regular password rotation, and full packet capture).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.