
Case study Enterprise
Stolen Sessions Put Administrative MFA at Risk
Unit6 found an administrator’s credentials and session material in adversary possession. Together, they created a path around the next MFA prompt. Any later account use or defensive response remains unconfirmed.
Impact summary
Unit6 found an administrator’s credentials and session material in adversary possession. Together, they created a path around the next MFA prompt. Any later account use or defensive response remains unconfirmed.

01 / Observation
What Unit6 saw
Unit6 observed the attacker-side material, including:
- 01
Credentials associated with a privileged account
- 02
Session tokens that could preserve authenticated access
- 03
An access-broker connection linking the material to adversary activity
02 / Significance
Why it mattered
MFA can protect a login while leaving an already authenticated session as a separate access path.
An attacker had obtained material tied to a system administrator. A password reset alone might not address an active session token.
03 / Confidence
How Unit6 established confidence
Credentials and session material were in adversary possession
The material was in adversary hands. Follow-on intrusion and customer containment were not confirmed.
04 / Recommended response
What the customer could do
The evidence called for a response across both credentials and sessions:
- Reset the affected credentials and review administrator activity
- Invalidate active sessions and rotate associated authentication material
- Check for new trusted devices, persistence, or unusual privileged changes
05 / Outcome not confirmed
Outcome
The attacker-held combination could have allowed administrative access without another MFA prompt.
Whether the organization revoked the material or the actor used it further remains unknown.



