Okta Support Breach 2023: Session Tokens Beat MFA Again

Attackers compromised an Okta support engineer’s personal device, stole the session cookies inside it, and used Okta’s own support console against a customer base estimated at five percent of tenants. BeyondTrust, 1Password, and Cloudflare each detected the downstream activity independently — before the full scope was confirmed.

Continue ReadingOkta Support Breach 2023: Session Tokens Beat MFA Again

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia’s Midnight Blizzard a foothold inside Microsoft’s own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

23andMe Credential Stuffing: When Relatives Are the Payload

Reused passwords took over 14,000 23andMe accounts, then the DNA Relatives feature amplified the access into profile data for 6.9 million genetically-linked users. The October 2023 breach rewrote breach math: your exposure now includes every relative’s password hygiene.

Continue Reading23andMe Credential Stuffing: When Relatives Are the Payload

Mr. Cooper Mortgage Breach: The Week Payments Stopped

When one of America’s largest mortgage servicers went dark for a week, the harm went far beyond stolen data. The Mr. Cooper incident — detected October 24, disclosed October 31, 2023 — halted payments, escrow, and payoffs for millions of borrowers, and later filings put the notification count near 14.7 million people with Social Security numbers and bank account details in the mix. This account covers the stolen-credential entry, the outage that regulators treated as the real injury, the mortgage-sector dependencies that amplified it, and the durable lessons for any payment-critical firm.

Continue ReadingMr. Cooper Mortgage Breach: The Week Payments Stopped

Magecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

Through 2024, digital skimming returned to threat reports’ front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io’s June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0’s script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.

Continue ReadingMagecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

TfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

On September 5, 2024, Transport for London detected an intrusion begun days earlier through social engineering of staff — and within a week a 17-year-old was arrested, then charged under the Computer Misuse Act, for a breach that exposed contact details and the bank details of roughly 3,000 Oyster refund customers. This account reconstructs the phishing entry, the lateral movement, the containment that took status boards and the refund portal offline, the NCSC-NCA response, and the municipal-security lessons that outlasted the headlines.

Continue ReadingTfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos