Incident case studies

Real incidents. One practical prevention step each. Sources linked every time.

Target (2013): third‑party HVAC credentials → network access

Attackers reportedly entered Target via credentials stolen from an HVAC/refrigeration vendor with remote access.

Prevention: Vendor access controls: least privilege, separate network segments, and strong MFA for third‑party access.

Source: U.S. Senate Committee report (PDF). ([commerce.senate.gov](https://www.commerce.senate.gov/services/files/24d3c229-4f2f-405d-b8db-a3a67f183883?utm_source=chatgpt.com))

Equifax (2017): unpatched Apache Struts vulnerability

Equifax stated the attack vector was a vulnerability in Apache Struts (CVE‑2017‑5638) affecting its dispute portal.

Prevention: Patch management: apply known security fixes quickly; maintain asset inventory and patch SLAs.

Sources: Equifax press release; NIST NVD CVE entry. ([investor.equifax.com](https://investor.equifax.com/news-events/press-releases/detail/237/equifax-releases-details-on-cybersecurity-incident?utm_source=chatgpt.com))

Colonial Pipeline (2021): single compromised VPN password

Public reporting described access gained via a single compromised password, contributing to major operational disruption.

Prevention: MFA on remote access + disable/limit legacy VPN accounts; monitor for stolen-credential reuse.

Source: Reuters. ([reuters.com](https://www.reuters.com/business/colonial-pipeline-ceo-tells-senate-cyber-defenses-were-compromised-ahead-hack-2021-06-08/?utm_source=chatgpt.com))

“Celebgate” (2012–2014): phishing into iCloud/Gmail accounts

A U.S. DOJ case describes a phishing scheme that accessed hundreds of iCloud/Gmail accounts, including celebrities.

Prevention: Phishing resistance: MFA + never provide credentials via email; verify account alerts immediately.

Source: U.S. Department of Justice press release. ([justice.gov](https://www.justice.gov/usao-cdca/pr/illinois-man-charged-hacking-apple-icloud-and-gmail-accounts-belonging-more-300-people?utm_source=chatgpt.com))

WannaCry (2017): wormable Windows SMB vulnerability

WannaCry spread rapidly by exploiting SMB vulnerabilities addressed in MS17‑010.

Prevention: Patch critical vulns quickly; disable SMBv1 where applicable; segment networks to limit worm spread.

Source: NHS Digital cyber alert on MS17‑010/SMB. ([digital.nhs.uk](https://digital.nhs.uk/cyber-alerts/2017/cc-1411?utm_source=chatgpt.com))

NotPetya (2017): destructive malware with global impact

NotPetya caused widespread disruption beyond Ukraine, affecting many organizations internationally.

Prevention: Resilience: backups + rapid isolation; supply-chain/update risk controls; strong segmentation.

Source: CISA alert. ([cisa.gov](https://www.cisa.gov/news-events/alerts/2017/07/01/petya-ransomware?utm_source=chatgpt.com))

Twitter (2020): social engineering → internal tools abuse

A public investigation report described a coordinated social engineering attack used to access internal systems/tools.

Prevention: Reduce internal tool access, strengthen helpdesk identity verification, and harden employee auth flows.

Source: NY Department of Financial Services report. ([dfs.ny.gov](https://www.dfs.ny.gov/Twitter_Report?utm_source=chatgpt.com))

Uber (2022): MFA “push fatigue” + impersonated IT support

Reporting and analysis described repeated MFA pushes until a user accepted, enabling further access.

Prevention: Use number-matching/stronger MFA, limit push-based approvals, and train for helpdesk impersonation.

Sources: Uber security update; third‑party breach analysis. ([uber.com](https://www.uber.com/en-FR/newsroom/security-update/?utm_source=chatgpt.com))

MGM Resorts (2023): major outage during cybersecurity incident

MGM reported disruptions and shut down some systems while investigating; the FBI confirmed an investigation.

Prevention: Strong identity verification at service desks + least privilege + rapid containment playbooks.

Source: Associated Press. ([apnews.com](https://apnews.com/article/ea48f926c5a732e735e7572d19339444?utm_source=chatgpt.com))

JBS (2021): ransomware → operational disruption + ransom paid

Public reporting indicates JBS paid $11M in response to a ransomware attack impacting operations.

Prevention: Resilience + segmentation + tested backups; harden identity and remote access; incident response planning.

Source: Reuters. ([reuters.com](https://www.reuters.com/technology/jbs-paid-11-mln-response-ransomware-attack-2021-06-09/?utm_source=chatgpt.com))

Ready to measure your posture?

Take the assessment for an XY plot + the highest-impact fixes for you.

Start assessment