Index live· 1,284 files · 148 editions
ForensicPost

Search the index

9 results
Try
Results for “Valid credentials”Newest first
26-0608
File

Nobody Breached Anything; They Just Logged In

Valid credentials from somebody else’s breach, accepted. Nothing failed in the conventional sense, and customer data went anyway.

UnattributedCredential stuffingRetailIdentity
Sev 3TargetChick-fil-AActorUnattributed
25-0612
File

Compromised Account Downloaded 300,000 Texas Crash Reports

A crash report exists because someone was in a collision. No vulnerability was exploited — a valid account did a permitted thing 300,000 times.

UnattributedCompromised credentialsPublic sectorPublic sector
Sev 3TargetTexas Department of TransportationActorUnattributedUSA
25-0421b
File

Compromised Credentials Led the Root Causes at 41%, Against 22% for Exploits

The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.

MultipleValid credentialsMultipleMethod
Sev 4TargetIncident response caseloadActorMultiple
24-0712
File

AT&T Says Call and Text Records for Nearly All Mobile Customers Were Taken

A number is not a name until somebody looks it up, and looking it up is trivial. What the set contains is a contact graph.

UNC5537Valid credentials, no MFATelecomConcentration
Sev 5TargetAT&TActorUNC5537USA
24-0620
File

Change Healthcare Affected-Person Count Took Eleven Months to Settle

It did not grow because the intrusion grew. It grew because working out whose records sit in four terabytes takes eleven months.

ALPHVValid credentials, no MFAHealthcareVerification
Sev 5TargetChange HealthcareActorALPHVUSA
24-0531
File

Five Hundred and Sixty Million, Claimed

A 560 million claim graded low sits below a 110 million disclosure graded high. That ordering is the point of having grades.

UNC5537Valid credentials, no MFAEntertainmentVerification
Sev 4TargetTicketmasterActorUNC5537USA
24-0530
File

Attackers Logged Into Snowflake Customer Environments With Working Credentials

The platform behaved correctly at every step and 165 organisations lost data anyway. There was no CVE to index it under.

UNC5537Valid credentials, no MFAMultipleIdentity
Sev 5TargetSnowflake tenantsActorUNC5537
24-0221
File

The Change Healthcare Theft and the Ransomware Were a Week Apart

Encryption is the moment the attacker chooses to be seen. It happens after the theft, because the theft is the leverage.

ALPHVValid credentials, no MFAHealthcareDwell
Sev 5TargetChange HealthcareActorALPHVUSA
24-0212
File

Change Healthcare Intruders Used a Citrix Portal With No Second Factor

A written requirement that MFA be enabled everywhere is not a control. It is intent somebody then has to enforce against an estate nobody has fully inventoried.

ALPHVValid credentials, no MFAHealthcareIdentity
Sev 5TargetChange HealthcareActorALPHVUSA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging