Skip to case study
All case studies

Case study IT Services

Persistence at a Service Provider Exposed a Wider Path

Unit6 observed a threat actor with persistence across several systems at a managed service provider. Because that provider connects to other organizations, the confirmed internal breach created a wider supply-chain concern.

ThreatA managed service provider was compromised during a campaign aimed at connected organizations
What Unit6 sawPersistence across provider systems
What was at riskCross-organization access risk surfaced

Impact summary

Unit6 observed a threat actor with persistence across several systems at a managed service provider. Because that provider connects to other organizations, the confirmed internal breach created a wider supply-chain concern.

Illustrative close-up of separate access cards beside a disconnected cable

01 / Observation

What Unit6 saw

Unit6 telemetry connected the actor to:

  1. 01

    Persistent access within the provider’s environment

  2. 02

    Compromise spanning communications, identity, virtual-desktop, and customer-management systems

  3. 03

    An apparent objective of reaching organizations connected to the provider

02 / Significance

Why it mattered

A provider’s trusted access can make one organization’s breach relevant to many others.

The provider’s internal systems were breached. Compromise of its customers was not confirmed.

03 / Confidence

How Unit6 established confidence

Persistence across multiple internal service-provider systems

Neither a completed downstream intrusion nor a post-notification response was confirmed.

04 / Recommended response

What the customer could do

The evidence warranted a response at both the provider and trust boundaries:

  • Investigate and contain the provider’s compromised systems and identities
  • Review privileged connections to customer and supplier environments
  • Rotate shared secrets and monitor cross-organization access for misuse

05 / Outcome not confirmed

Outcome

The confirmed persistence gave the actor a platform from which connected environments might be targeted.

Whether those trust paths were used or closed remains unknown.

See what happens when you know first.

You’ve seen their hands.
Now let’s look at yours.

Book a demo