An illustrative case explaining the route
A provider compromise that reached its clients' environments
A managed IT provider looking after infrastructure for a number of small clients. It uses one remote management tool, and an admin account repeated with the same password across environments because it is 'faster for support'. Compromising a single account at the provider opened the door to more than one client environment the same night.
Technology & managed service providers
What was affected
- The provider's remote management server.
- File servers in two client environments.
- Backup repositories managed with the same credential.
- A hosting control panel for a third client.
What had been tried before it reached us
- Changing the admin account's password alone, leaving existing sessions open.
- Restoring a client copy into its environment before attacker access was removed.
- Stopping the management tool rather than isolating it, losing important logs.
The route
- 01
Containment before recovery
Open sessions were terminated and tokens revoked, not just the password — changing a password does not end a live session.
- 02
Separating client environments
Each environment was treated as an independent case with its own access path, and no new shared credential was permitted.
- 03
Preserving what logs remained
Management tool and hosting panel logs were collected before any restart that might roll them over.
- 04
Checking backups before trusting them
Repositories were examined: which had been managed with the compromised credential, and which stayed out of its reach.
- 05
Rebuild rather than clean
The management server was rebuilt from scratch instead of cleaned, because the attacker's scope on it could not be established precisely.
The outcome
What came back
- Two client environments from hosting provider snapshots not managed with the same credential.
- The third client's data from an offline copy it kept itself.
- Part of the management tool's configuration from older export files.
What did not
- Management tool logs for the period before the incident — the tool was stopped and the logs rolled over.
- A whole backup repository managed with the compromised credential and deleted before encryption.
- Network documentation for a small client with no second source.
What would have changed the outcome
- No shared admin credential between any two client environments, without exception.
- Temporary rights granted on demand that expire automatically.
- Backups the provider itself has no rights to delete.
- Log collection outside the tool that produces them.
Next step
Start free assessmentIsolate the device and keep the ransom note.
Send the file extension, the ransom note and a description of the affected devices. We assess the case without inaccurate promises.