@hetmehtaa: my company got breached the attacker had access for 11 days on day 3 he emailed our IT helpdesk complained that the VPN…
Summary
A humorous yet alarming account of a company breach where the attacker, after 3 days of access, contacted IT helpdesk complaining about slow VPN, was given a password reset and upgraded access, then rated IT support 5 stars before being discovered during forensics.
View Cached Full Text
Cached at: 05/18/26, 04:33 PM
my company got breached
the attacker had access for 11 days
on day 3 he emailed our IT helpdesk complained that the VPN was slow
our helpdesk reset his password upgraded his access tier to fix the “connectivity issue”
and closed the ticket as resolved
CSAT score: 5 stars
we found this in the logs during forensics
the attacker had rated our IT support excellent
Similar Articles
Massive breach spills credentials for thousands of sensitive networks
A massive breach exposed credentials for thousands of sensitive networks, including a NATO defense contractor, with attackers using a 45-GPU cluster to crack VPN authentication hashes and compromise Active Directory environments.
Hackers shoveled snow for company, were rewarded with network admin access
Red teamers gained physical access to a client's building by shoveling snow and then achieved network admin access, highlighting the importance of physical security awareness.
Terabytes of credentials leaked in massive supply-chain attack
A massive supply-chain attack on the open-source AI tool LiteLLM exposed terabytes of credentials from thousands of organizations, including Microsoft, Amazon, and Cisco, during a 40-minute window in March. Security firms CloudSEK and Hudson Rock disclosed the breach, attributing it to the TeamPCP gang.
Three hours. One stolen password. An entire cloud environment compromised.
Anthropic's threat intelligence report reveals how criminals use AI agents to automate cyberattacks, highlighting that traditional security measures may be insufficient for automated threats.
My Homelab Got Hacked - A Postmortem
A homelab owner details how their Forgejo instance was hacked via CVE-2026-60004, an RCE in Gitea, and shares the postmortem including mistakes made and exploit analysis.