Skip to main content

Public breach analyses

Famous breaches, read from the inside

Each of these incidents started with one foothold. We follow what the published record says happened next, and ask at each step what would have stopped it, what would have caught it, and what a test would have shown first.

Analysis of a public incident, based on published reports. Assumed Breach was not involved.

Every factual statement links to a primary or authoritative source: the company's own filings and statements, congressional testimony, government advisories, or published threat intelligence. Where a widely repeated detail is not in those sources, the analysis says so and leaves it out. For our own work, see the case studies.

  1. BA-01September 2022

    Uber, 2022: a bought password and an accepted login prompt

    A contractor's password, likely bought after malware on a personal device, then repeated two-factor prompts until one was accepted. What the attacker reached next, by Uber's own account, and which controls would have stopped or caught each step.

    Way in
    A contractor's stolen password, then a two-factor prompt the contractor accepted
    The missing control
    Phishing-resistant MFA that a flood of approval prompts cannot wear down
  2. BA-02September 2023

    Caesars, 2023: social engineering at the IT support vendor

    Caesars told the SEC that suspicious activity in its network came from a social engineering attack on an outsourced IT support vendor, and that a copy of its loyalty program database was taken. What published advisories say about the technique, and which controls would have stopped or caught each step.

    Way in
    A social engineering attack on an outsourced IT support vendor, in the filing's words; the method is not described
    The missing control
    If the vendor's support desk could be talked into a reset, identity checks there that persuasion cannot get past
  3. BA-03February 2024

    Change Healthcare, 2024: a remote access portal without MFA

    UnitedHealth Group's chief executive told Congress that attackers used compromised credentials on a Citrix remote access portal that did not have multi-factor authentication. What happened in the nine days before the ransomware, and which controls would have stopped or caught each step.

    Way in
    Compromised credentials on a Citrix remote access portal
    The missing control
    Multi-factor authentication on an internet-facing remote access portal
  4. BA-042024

    Snowflake customer accounts, 2024: old passwords, no MFA

    Mandiant traced a campaign against Snowflake customer accounts to credentials stolen by infostealer malware, some of them years old, used against accounts with no multi-factor authentication and no network allow list. What the actor did with them, and which controls would have stopped each step.

    Way in
    Valid customer credentials harvested by infostealer malware
    The missing control
    MFA, credential rotation and network allow lists on the customer accounts