Active Directory flaw exposed company passwords to hackers
TL;DR. A company stored service account passwords in Active Directory description fields, allowing initial access brokers to compromise the entire domain. - Attackers gained full domain access after a phishing campaign captured victim credentials and queried Active Directory. - The security lapse enabled hackers to delete backups and deploy ransomware, paralyzing 2000+ users for months. - This incident highlights critical vulnerabilities in using cleartext password storage within enterprise IT environments.
- Passwords were stored in Active Directory description fields due to lack of a proper vault.
- A phishing campaign led to credential capture, allowing hackers to query Active Directory descriptions.
- Hackers accessed the entire domain, deleted backups, and deployed ransomware, taking the company offline for months.
Sources
- All the passwords were stored in Active Directory description fields — theregister.com