Active Directory flaw exposed company passwords to hackers

TL;DR. A company stored service account passwords in Active Directory description fields, allowing initial access brokers to compromise the entire domain. - Attackers gained full domain access after a phishing campaign captured victim credentials and queried Active Directory. - The security lapse enabled hackers to delete backups and deploy ransomware, paralyzing 2000+ users for months. - This incident highlights critical vulnerabilities in using cleartext password storage within enterprise IT environments.

Sources

Back to QLANKR News