After reaching the provider, the operators used its management platform to perform reconnaissance across customer systems, collecting device names and configurations, user accounts and network connection details before deploying encryptors.
The Platform Was Better Reconnaissance Than Any Intrusion
An attacker inside a single organisation must map it while avoiding detection — the expensive, noisy phase this desk described at 25-0611, where a stolen network diagram converts a future intrusion from exploration into navigation.
A management platform does that work as a feature. It holds an accurate, current, indexed inventory of every customer estate, because managing them requires one.
The reconnaissance was not an intrusion technique. It was reading a dashboard.
Which Turns The Attack Into A Selection Problem
With a customer list and configuration detail, an operator can choose which downstream organisations to hit — by size, by sector, by apparent backup posture, by whichever looks most likely to pay.
The corpus filed at 25-1125 that the 102-day Nevada dwell was the operation, and the deployment was the last act. Here the equivalent preparation took reading rather than moving, which compresses the window in which anyone could notice.
And It Means The Downstream Victims Were Chosen
The corpus normally records supplier incidents where every downstream customer is affected because their data sat in one place — Marquis at 25-0814, Chain IQ at 25-0613.
This is different. The customers were not incidentally exposed; they were surveyed and picked. Whichever organisations were not encrypted were spared by a decision, not by a control.
Compiled from published vendor research, listed below. The selection criteria used by the operators are not established and are not asserted here. Corrections: corrections@forensicpost.com.