Lessons learned from a Man-in-the-Middle attack
ID: eda980e2-1d0c-5d85-b7d3-daa3a3530500
STIX ID: report--eda980e2-1d0c-5d85-b7d3-daa3a3530500
Feed Name: Fox-IT blog
Fox-IT reports a September 19, 2017 incident in which an attacker obtained access to their third-party domain registrar account, modified DNS records and deployed a fraudulent SSL certificate to perform a Man-in-the-Middle attack against their ClientPortal and briefly redirect email; the attacker intercepted 12 file transfers (10 unique), credentials for nine users (2FA prevented misuse), and some user metadata. The incident was detected and contained within ~10 hours, law enforcement was engaged, affected parties notified, and Fox-IT published remediation steps and recommendations (use of 2FA at registrars, certificate transparency monitoring, regular password rotation, and full packet capture).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
