Skip to case study
All case studies

Case study Pharmaceuticals

A trusted provider became a path toward ransomware

A pharmaceutical company severed trusted SaaS access after Unit6 detected an attacker pivoting through a compromised provider toward ransomware staging.

ThreatA compromised business intelligence SaaS provider became a route into a global pharmaceutical company
What Unit6 sawTrusted SaaS admin pathway
OutcomeStopped in the staging phase

Impact summary

A pharmaceutical company severed trusted SaaS access after Unit6 detected an attacker pivoting through a compromised provider toward ransomware staging.

Illustrative close-up of an access token and disconnected cable in a laboratory workspace

01 / Observation

What Unit6 saw

Unit6 connected activity across the SaaS and customer environments and identified:

  1. 01

    Authenticated access to pharmaceutical systems through the provider’s admin API

  2. 02

    Scanning of internal shares, privileged directories, and user accounts

  3. 03

    Attempts to escalate privileges and establish persistence with SaaS service accounts

  4. 04

    Staging behavior consistent with known ransomware tradecraft

02 / Significance

Why it mattered

A global pharmaceutical company consumed services from a business intelligence platform whose privileged administrator access had been compromised.

The attacker began pivoting from the SaaS provider into multiple customers through legitimate, whitelisted integration links, bypassing traditional perimeter defenses.

Trusted credentials gave the actor privileged visibility into research environments. A ransomware event could have disrupted manufacturing or exposed regulated patient data.

03 / Confidence

How Unit6 established confidence

Trusted admin API access, internal enumeration, privilege escalation attempts, and ransomware pre-staging

Correlating the compromised provider with customer-side activity exposed the actor’s pre-ransomware sequence while it was still in progress.

04 / Response

What the customer could do

Unit6 and the response team acted across three access layers:

  • Invalidated authentication tokens and API keys, and separated integrations from production
  • Reset credentials and required fresh MFA enrollment for high-value identities
  • Enabled endpoint response controls and isolated backups against encryption risk

05 / Documented outcome

Outcome

The ransomware attack was blocked in the staging phase, with zero payloads deployed.

The team gained visibility across the SaaS-to-customer attack chain and closed the trusted pathway the actor had used.

See what happens when you know first.

You’ve seen their hands.
Now let’s look at yours.

Book a demo