Incident Case Studies
Real incidents. One practical prevention step each. Sources linked every time.

Target (2013): third‑party HVAC credentials → network access

Attackers reportedly entered Target via credentials stolen from an HVAC/refrigeration vendor with remote access.

Prevention: Vendor access controls: least privilege, separate network segments, and strong MFA for third‑party access.

Source: U.S. Senate Commerce Committee report (PDF)

Equifax (2017): unpatched Apache Struts vulnerability

Equifax stated the attack vector was a vulnerability in Apache Struts (CVE‑2017‑5638) affecting its dispute portal.

Prevention: Patch management: apply known security fixes quickly; maintain asset inventory and patch SLAs.

Sources: Equifax press release; NIST NVD CVE entry.

Colonial Pipeline (2021): single compromised VPN password

Public reporting described access gained via a single compromised password, contributing to major operational disruption.

Prevention: MFA on remote access + disable/limit legacy VPN accounts; monitor for stolen-credential reuse.

Source: Reuters

"Celebgate" (2012–2014): phishing into iCloud/Gmail accounts

A U.S. DOJ case describes a phishing scheme that accessed hundreds of iCloud/Gmail accounts, including celebrities.

Prevention: Phishing resistance: MFA + never provide credentials via email; verify account alerts immediately.

Source: U.S. Department of Justice press release

WannaCry (2017): wormable Windows SMB vulnerability

WannaCry spread rapidly by exploiting SMB vulnerabilities addressed in MS17‑010.

Prevention: Patch critical vulns quickly; disable SMBv1 where applicable; segment networks to limit worm spread.

Source: NHS Digital cyber alert on MS17‑010/SMB

NotPetya (2017): destructive malware with global impact

NotPetya caused widespread disruption beyond Ukraine, affecting many organizations internationally.

Prevention: Resilience: backups + rapid isolation; supply-chain/update risk controls; strong segmentation.

Source: CISA alert

Twitter (2020): social engineering → internal tools abuse

A public investigation report described a coordinated social engineering attack used to access internal systems/tools.

Prevention: Reduce internal tool access, strengthen helpdesk identity verification, and harden employee auth flows.

Source: NY Department of Financial Services report

Uber (2022): MFA "push fatigue" + impersonated IT support

Reporting and analysis described repeated MFA pushes until a user accepted, enabling further access.

Prevention: Use number-matching/stronger MFA, limit push-based approvals, and train for helpdesk impersonation.

Source: Uber security update

MGM Resorts (2023): major outage during cybersecurity incident

MGM reported disruptions and shut down some systems while investigating; the FBI confirmed an investigation.

Prevention: Strong identity verification at service desks + least privilege + rapid containment playbooks.

Source: Associated Press

JBS (2021): ransomware → operational disruption + ransom paid

Public reporting indicates JBS paid $11M in response to a ransomware attack impacting operations.

Prevention: Resilience + segmentation + tested backups; harden identity and remote access; incident response planning.

Source: Reuters

Ready to measure your posture?

Take the free assessment — get a scored XY plot and your highest-impact fixes.

Start assessment →