logo

U.S. State Government Network Breached via Former Employee's Account

ID: db6b8f70-f63c-51b4-a794-49eb9663da46

STIX ID: report--db6b8f70-f63c-51b4-a794-49eb9663da46

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-02-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA and MS-ISAC warn that an unnamed U.S. state government network was breached when a former employee's admin credentials—apparently exposed in a separate leak—were used to access an internal VPN and virtual machines, retrieve stored administrative credentials with both on-premises and Azure (Entra ID) privileges, perform LDAP queries, and publish host and user data on the dark web; no cloud lateral movement was observed and MFA was not enabled on the compromised accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.