logo

MFA Failure Enables Infostealer Breach At 50 Enterprises

ID: bb6891c9-43a3-5e7e-b486-29bc6d8d31b5

STIX ID: report--bb6891c9-43a3-5e7e-b486-29bc6d8d31b5

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

...
...

A financially motivated actor dubbed Zestix/Sentap used harvested credentials from infostealer logs (RedLine, Lumma, Vidar) to access cloud file-sharing services lacking MFA, exfiltrating large volumes of sensitive data from dozens of global organizations (including an airline, law firm, healthcare provider and defense contractor) and offering the stolen data for sale, underscoring failures in credential hygiene and session management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.