An illustrative case explaining the route

A provider compromise that reached its clients' environments

A managed IT provider looking after infrastructure for a number of small clients. It uses one remote management tool, and an admin account repeated with the same password across environments because it is 'faster for support'. Compromising a single account at the provider opened the door to more than one client environment the same night.

Technology & managed service providers

What was affected

  • The provider's remote management server.
  • File servers in two client environments.
  • Backup repositories managed with the same credential.
  • A hosting control panel for a third client.

What had been tried before it reached us

  • Changing the admin account's password alone, leaving existing sessions open.
  • Restoring a client copy into its environment before attacker access was removed.
  • Stopping the management tool rather than isolating it, losing important logs.

The route

  1. 01

    Containment before recovery

    Open sessions were terminated and tokens revoked, not just the password — changing a password does not end a live session.

  2. 02

    Separating client environments

    Each environment was treated as an independent case with its own access path, and no new shared credential was permitted.

  3. 03

    Preserving what logs remained

    Management tool and hosting panel logs were collected before any restart that might roll them over.

  4. 04

    Checking backups before trusting them

    Repositories were examined: which had been managed with the compromised credential, and which stayed out of its reach.

  5. 05

    Rebuild rather than clean

    The management server was rebuilt from scratch instead of cleaned, because the attacker's scope on it could not be established precisely.

The outcome

What came back

  • Two client environments from hosting provider snapshots not managed with the same credential.
  • The third client's data from an offline copy it kept itself.
  • Part of the management tool's configuration from older export files.

What did not

  • Management tool logs for the period before the incident — the tool was stopped and the logs rolled over.
  • A whole backup repository managed with the compromised credential and deleted before encryption.
  • Network documentation for a small client with no second source.

What would have changed the outcome

  • No shared admin credential between any two client environments, without exception.
  • Temporary rights granted on demand that expire automatically.
  • Backups the provider itself has no rights to delete.
  • Log collection outside the tool that produces them.

Isolate the device and keep the ransom note.

Send the file extension, the ransom note and a description of the affected devices. We assess the case without inaccurate promises.