Misconfigurations in IT environments continue to be a leading cause of cyber breaches, as highlighted by security experts who emphasize that simple errors such as open cloud storage, default credentials, and improper access controls are frequently exploited by attackers. Security leaders urge organizations to prioritize configuration management and align with compliance frameworks like NIST, CIS, HIPAA, and ISO 27001 to reduce risk exposure. Tools such as ThreatLocker's Defense Against Configurations (DAC) are being developed to help organizations identify and remediate these vulnerabilities before they can be exploited.
A recent large-scale cybercrime campaign, dubbed 'Jingle Thief,' demonstrates the real-world impact of these weaknesses, particularly in the retail sector. The Morocco-based group targets global retailers by leveraging stolen Microsoft 365 credentials to infiltrate cloud environments, maintain long-term access, and generate fraudulent gift cards for resale. Attackers often remain undetected for months, compromising dozens of accounts and using legitimate tools to evade detection, underscoring the urgent need for robust configuration management and credential security in cloud-based infrastructures.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
On publication of its findings, Unit 42 described the campaign as 'Jingle Thief' and attributed it to a Morocco-based cybercrime group. The report detailed how the actors used phishing or smishing, SharePoint and OneDrive reconnaissance, internal phishing, and abuse of Microsoft Entra ID self-service features to persist in victim environments.
Palo Alto Networks Unit 42 identified a large-scale campaign targeting global retailers and consumer services firms that rely heavily on cloud infrastructure. In at least one case, the attackers maintained access for 10 months by compromising dozens of employee Microsoft 365 accounts and blending in with normal business activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.