upvote
There are typically quite a few steps between initial access and domain domination, which I assume is what they ended up with, considering they have administrator account passwords. Well, unless you are using 123456 as the password for an admin account.
reply
Yes and no.

The problem with the compromised platform is that it had no MFA. If they had just had something like OAuth via google workspace or something, this most likely could have been avoided. But it seems like they just had completely vanilla email/password auth with zero additional security measures.

reply