MKT—KSA / 06

Attacks on companies and nations

An expanded archive of documented attack paths, disruption and response across companies, nations and critical systems.

  1. 2024-02-2101
    Healthcare / United States

    Change Healthcare

    01

    Path

    Access using compromised credentials to an environment without multifactor authentication.

    02

    Impact

    Claims, payment and prescription services were disrupted nationally, affecting healthcare providers.

    Open case file ↗
  2. 2023-05-3102
    Multiple organizations / Global

    MOVEit Transfer exploitation

    01

    Path

    Exploitation of a SQL-injection flaw in internet-facing MOVEit Transfer instances to steal data.

    02

    Impact

    Multiple organizations faced data theft and extortion; impact varies by each official disclosure.

    Open case file ↗
  3. 2023-09-1103
    Hospitality / United States

    MGM Resorts

    01

    Path

    A cybersecurity issue affected IT systems; the initial filing did not specify the entry path.

    02

    Impact

    The company shut down systems as a precaution and experienced operational disruption.

    Open case file ↗
  4. 2022-07-1504
    Government / Albania

    Albania government networks

    01

    Path

    State-sponsored actors used initial access followed by wiping and destructive tooling against government networks.

    02

    Impact

    Digital government services were disrupted and systems and data were damaged in a documented destructive campaign.

    Open case file ↗
  5. 2022-04-1705
    Government / Costa Rica

    Costa Rica — Conti

    01

    Path

    A ransomware campaign targeted government bodies; the government source did not publish the complete entry path.

    02

    Impact

    Customs and tax platforms were disrupted, affecting foreign trade and public services.

    Open case file ↗
  6. 2022-02-2406
    Satellite communications / Ukraine and Europe

    Viasat KA-SAT

    01

    Path

    A cyber operation targeted the KA-SAT network as Russia's invasion of Ukraine began.

    02

    Impact

    A significant satellite-communications outage affected users in Ukraine and several European countries.

    Open case file ↗
  7. 2021-05-0707
    Energy / United States

    Colonial Pipeline

    01

    Path

    DarkSide-linked ransomware led to precautionary shutdowns across parts of the infrastructure.

    02

    Impact

    Fuel supply across the U.S. East Coast was disrupted, producing market and operational effects.

    Open case file ↗
  8. 2021-03-0208
    Mail servers / Global

    Microsoft Exchange on-premises

    01

    Path

    Exploitation of on-premises Exchange flaws to reach email and install web shells.

    02

    Impact

    Multiple organizations faced unauthorized access and persistence inside mail servers.

    Open case file ↗
  9. 2020-12-1309
    Government and enterprise / Supply chain

    SolarWinds Orion

    01

    Path

    Malicious code inside signed, trusted Orion updates reached customer networks.

    02

    Impact

    Long-lived covert access to government and private networks, including data and credential theft.

    Open case file ↗
  10. 2017-06-2710
    Enterprise and government / Global

    NotPetya

    01

    Path

    A compromised M.E.Doc update was followed by internal spread through SMB, credentials and administrative tools.

    02

    Impact

    Broad disruption and irrecoverable encryption affected transport, pharmaceuticals, government and other sectors, with losses in the billions.

    Open case file ↗
  11. 2017-05-1211
    National healthcare / United Kingdom

    NHS — WannaCry

    01

    Path

    Worm propagation through unpatched Windows systems and SMBv1 flaws.

    02

    Impact

    Hospitals and practices were disrupted, cancelling thousands of appointments and procedures.

    Open case file ↗
  12. 2017-05-1312
    Credit data / United States

    Equifax

    01

    Path

    Exploitation of a web-application vulnerability to reach internal files.

    02

    Impact

    Personal data belonging to millions of consumers was exposed, including identifiers and sensitive financial records.

    Open case file ↗
  13. 2016-02-0413
    Financial sector / Bangladesh

    Bangladesh Bank cyber theft

    01

    Path

    Compromise of the bank environment and fraudulent SWIFT messages in an international bank-theft campaign.

    02

    Impact

    Attackers transferred tens of millions of dollars, while additional transfers were stopped after detection.

    Open case file ↗
  14. 2015-12-2314
    Energy / Ukraine

    Ukraine power distribution

    01

    Path

    Access to electricity-distribution networks was followed by operational control and deliberate system disruption.

    02

    Impact

    Power was lost for a large customer population, while call centers and operational components were affected.

    Open case file ↗
  15. 2015-06-0415
    Government personnel data / United States

    U.S. Office of Personnel Management

    01

    Path

    Compromise of personnel and background-investigation systems; the public summary does not provide the complete entry path.

    02

    Impact

    Current and former employee data, background-investigation records and fingerprints were exposed across linked incidents.

    Open case file ↗
  16. 2012-08-1516
    Energy / Saudi Arabia

    Shamoon / Saudi Aramco

    01

    Path

    The initial entry vector was not officially resolved; the malware propagated inside the business environment through network shares.

    02

    Impact

    The malware wiped workstation data and disrupted a large part of the business network while production systems remained isolated.

    Open case file ↗