logo

How Poorly Secured Service Accounts Lead to Breaches

ID: 30735d7e-79c9-54bf-95ac-bd9460824a06

STIX ID: report--30735d7e-79c9-54bf-95ac-bd9460824a06

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2024-08-22

Date Updated: 2026-04-29

...
...

Executive summary: ReliaQuest highlights that service accounts are increasingly being exploited—85% of sampled breaches (Jan–Jul 2024) involved compromised service accounts—using techniques such as Kerberoasting, credential dumping, and weak/default passwords; a documented incident shows a service-account takeover leading to domain compromise, 100+GB exfiltration and BlackSuit ransomware deployment. The report outlines detection and remediation measures (logging, AES Kerberos, gMSAs, least privilege) and forecasts continued abuse of service accounts by diverse threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.