Skip to case study
All case studies

Case study Enterprise

Supplier Sessions Opened a Secure-Transfer Path

Unit6 sensors observed an access broker attempting to reach a secure email and file-transfer service with supplier credentials and authentication cookies. Possession of both reduced the protection a fresh login challenge would otherwise provide.

ThreatAn access broker used material obtained through supplier compromises
What Unit6 sawSupplier credentials and session cookies
What was at riskTrusted session path exposed

Impact summary

Unit6 sensors observed an access broker attempting to reach a secure email and file-transfer service with supplier credentials and authentication cookies. Possession of both reduced the protection a fresh login challenge would otherwise provide.

Illustrative close-up of two unmarked access cards and a sealed transfer case

01 / Observation

What Unit6 saw

Unit6’s sensors connected:

  1. 01

    An initial access broker attempting to use the secure transfer service

  2. 02

    Valid credentials tied to authorized supplier accounts

  3. 03

    Authentication cookies that could preserve a signed-in web session

02 / Significance

Why it mattered

Trusted suppliers often have access to systems where sensitive information moves between organizations.

Here the actor had both supplier credentials and session cookies. An access attempt was observed; data exfiltration from the target service was not confirmed.

03 / Confidence

How Unit6 established confidence

Valid passwords and authentication cookies used in attempted access to secure transfer

Supplier identities and the exact service name are withheld to protect the affected parties.

04 / Recommended response

What the customer could do

The evidence called for action on the supplier trust path:

  • Invalidate affected sessions and rotate supplier credentials
  • Review transferred files and access logs for unexpected activity
  • Reassess supplier privileges, session controls, and shared access paths

05 / Outcome not confirmed

Outcome

The combination could have enabled immediate account takeover and possible data access through a trusted third party.

Neither exfiltration nor completed remediation was confirmed.

See what happens when you know first.

You’ve seen their hands.
Now let’s look at yours.

Book a demo