logo

Infostealers and Lack of MFA Led to Dozens of Major Breaches

ID: f17c9bb2-cd3f-5be4-aaa1-cfd1e0bbeb7c

STIX ID: report--f17c9bb2-cd3f-5be4-aaa1-cfd1e0bbeb7c

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Hudson Rock and follow-on reporting attribute dozens of breaches at major global companies to infostealer malware (e.g., RedLine, Lumma, Vidar) that harvested stored credentials which threat actor(s) using the aliases Zestix/Sentap then used to access ShareFile, OwnCloud, and Nextcloud instances lacking multi-factor authentication; stolen credentials were aggregated and auctioned on the dark web, and vendors like ownCloud advise immediate MFA enforcement, password resets, session invalidation, and log review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.