#breach
- News · Mar 25, 2025Claims of Oracle Cloud credential exposure prompt scrutiny
Reports of exposed cloud credentials drew attention to single-sign-on and federation hygiene, though details and scope were disputed.
- News · Jun 10, 2024Snowflake customer breaches tied to stolen credentials and missing MFA
A wave of breaches at Snowflake customers was attributed to stolen credentials and accounts without multifactor authentication, fueling major data theft.
- News · May 29, 2024Ticketmaster breach tied to stolen Snowflake credentials
Live Nation confirmed a breach of Ticketmaster data hosted in Snowflake, part of a campaign exploiting accounts without multifactor authentication.
- News · Apr 18, 2024Cisco discloses Duo telephony supplier breach exposing MFA SMS logs
Cisco Duo notified customers that a breach at a telephony provider exposed SMS multifactor message logs, underscoring the weakness of SMS-based MFA.
- News · Feb 21, 2024Change Healthcare ransomware attack began with credentials and no MFA
The Change Healthcare ransomware attack, one of the most disruptive in US healthcare, started with compromised credentials on a server lacking MFA.
- News · Jan 19, 2024Microsoft says Midnight Blizzard breached corporate email via a test account
Microsoft reported the Russia-linked Midnight Blizzard group accessed executive email after password-spraying a legacy test account without MFA.
- News · Jan 9, 202423andMe confirms credential-stuffing breach affecting millions
23andMe attributed a large data exposure to credential stuffing against accounts that reused passwords and lacked MFA, later leading to settlements.
- News · Oct 20, 2023Okta discloses breach of its customer support case management system
Okta disclosed that attackers accessed its support system using a stolen credential, exposing session tokens and prompting customers to harden configurations.
- News · Sep 14, 2023MGM Resorts disrupted by ransomware after help-desk social engineering
Attackers reportedly reset an employee credential via the help desk to breach MGM Resorts, a high-profile example of social engineering defeating identity controls.
- News · Jul 11, 2023Microsoft says Storm-0558 forged tokens to access Outlook accounts
Microsoft disclosed that a China-linked group, Storm-0558, forged authentication tokens using a stolen signing key to access email, intensifying scrutiny of token security.