Threat Intelligence Brief
Curated summary with source attribution
Source: orca.security
Threat Risk: High
Victim: Fortune 500 Company
Incident: Social engineering attack leading to Salesforce access, AWS lateral movement, and ransomware deployment.
Impact: Data theft from S3 buckets and deployment of ransomware across cloud infrastructure.
Attacker: ShinyHunters
Analysis: The attack demonstrates a critical failure in identity security where social engineering bypassed authentication via device authorization codes. The threat actor exploited poor secret management by discovering AWS credentials stored in plain text within support tickets, enabling rapid lateral movement. This highlights the systemic risk of credential sprawl across SaaS and cloud environments.
Recommendations: Implement strict policies and automated scanning to prevent storing cloud secrets in CRM or support ticket fields.; Educate employees on the dangers of sharing device authorization codes via phone or chat.; Enhance cross-platform log correlation to detect anomalous lateral movement between SaaS platforms and cloud infrastructure.
Source: Orca Security
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source