Lack of MFA Enables Vast Cloud Credential Heist Affecting 50 Enterprises
These articles are AI-generated summaries. Please check the original sources for full details.
Lack of MFA Is Common Thread in Vast Cloud Credential Heist
The threat actor “Zestix” successfully compromised approximately 50 enterprises by leveraging infostealers to obtain credentials and access file-sharing instances. Zestix is currently auctioning stolen data from these breaches, highlighting a critical security lapse.
This incident demonstrates a reliance on readily available infostealers like RedLine, Lumma, and Vidar, coupled with a widespread failure to implement basic security measures. The cost of these breaches, while not quantified in the article, is likely substantial given the number of affected organizations and the potential for data exfiltration.
Why This Matters
Current cloud security models often assume strong credential protection, but this attack reveals a significant gap where weak password hygiene and the absence of MFA render those models ineffective. Organizations invest heavily in perimeter security and vulnerability management, yet a simple lack of MFA bypasses these defenses, exposing sensitive data at scale.
Key Insights
- Zestix/Sentap activity: Threat actor active since January 2026.
- Infostealers over Exploits: Attackers prioritize credential harvesting via infostealers over complex exploit chains.
- MFA as a Mitigator: Implementing MFA is the single most effective control against this type of attack.
Practical Applications
- Use Case: Iberia airline and other impacted companies failed to enforce MFA on file-sharing platforms, leading to data breaches.
- Pitfall: Assuming password complexity alone is sufficient security; neglecting MFA creates an easily exploitable vulnerability.
References:
Continue reading
Next article
Microsoft Warns Misconfigured Email Routing Can Enable Internal Domain Phishing
Related Content
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
Amazon reports a new AWS crypto mining campaign abusing IAM credentials, ECS, EC2, and termination protection for persistence.
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign
Attackers misused Google Cloud Application Integration to send 9,394 phishing emails from Google domains, bypassing filters and stealing credentials.
Cybersecurity in 2025: Shift to Hardware Trust and AI-Driven Defense
Cybersecurity is evolving to prioritize hardware-backed authentication and AI-driven defense, responding to faster attacker velocity across cloud and endpoint environments.