Real incidents. One practical prevention step each. Sources linked every time.
Target (2013): third‑party HVAC credentials → network access
Attackers reportedly entered Target via credentials stolen from an HVAC/refrigeration vendor with remote access.
Prevention: Vendor access controls: least privilege, separate network segments, and strong MFA for third‑party access.
Source: U.S. Senate Commerce Committee report (PDF)
Equifax (2017): unpatched Apache Struts vulnerability
Equifax stated the attack vector was a vulnerability in Apache Struts (CVE‑2017‑5638) affecting its dispute portal.
Prevention: Patch management: apply known security fixes quickly; maintain asset inventory and patch SLAs.
Sources: Equifax press release; NIST NVD CVE entry.
Colonial Pipeline (2021): single compromised VPN password
Public reporting described access gained via a single compromised password, contributing to major operational disruption.
Prevention: MFA on remote access + disable/limit legacy VPN accounts; monitor for stolen-credential reuse.
Source: Reuters
"Celebgate" (2012–2014): phishing into iCloud/Gmail accounts
A U.S. DOJ case describes a phishing scheme that accessed hundreds of iCloud/Gmail accounts, including celebrities.
Prevention: Phishing resistance: MFA + never provide credentials via email; verify account alerts immediately.
Source: U.S. Department of Justice press release
WannaCry (2017): wormable Windows SMB vulnerability
WannaCry spread rapidly by exploiting SMB vulnerabilities addressed in MS17‑010.
Prevention: Patch critical vulns quickly; disable SMBv1 where applicable; segment networks to limit worm spread.
Source: NHS Digital cyber alert on MS17‑010/SMB
NotPetya (2017): destructive malware with global impact
NotPetya caused widespread disruption beyond Ukraine, affecting many organizations internationally.
Prevention: Resilience: backups + rapid isolation; supply-chain/update risk controls; strong segmentation.
Source: CISA alert
Twitter (2020): social engineering → internal tools abuse
A public investigation report described a coordinated social engineering attack used to access internal systems/tools.
Prevention: Reduce internal tool access, strengthen helpdesk identity verification, and harden employee auth flows.
Source: NY Department of Financial Services report
Uber (2022): MFA "push fatigue" + impersonated IT support
Reporting and analysis described repeated MFA pushes until a user accepted, enabling further access.
Prevention: Use number-matching/stronger MFA, limit push-based approvals, and train for helpdesk impersonation.
Source: Uber security update
MGM Resorts (2023): major outage during cybersecurity incident
MGM reported disruptions and shut down some systems while investigating; the FBI confirmed an investigation.
Prevention: Strong identity verification at service desks + least privilege + rapid containment playbooks.
Source: Associated Press
JBS (2021): ransomware → operational disruption + ransom paid
Public reporting indicates JBS paid $11M in response to a ransomware attack impacting operations.
Prevention: Resilience + segmentation + tested backups; harden identity and remote access; incident response planning.
Source: Reuters