CISA reported multiple intrusions into organizations’ cloud environments in which attackers exploited weak security configurations, particularly in remote-work settings that mixed corporate and personal devices. The activity included phishing for cloud credentials, brute-force login attempts, abuse of valid accounts, and manipulation of email services after compromise. In several cases, attackers created or modified email forwarding rules to redirect sensitive messages to attacker-controlled accounts, sent phishing emails from internal compromised mailboxes, and concealed security warnings by moving them into RSS-related folders.
The incidents also showed that multi-factor authentication was not always sufficient on its own: some brute-force attempts were blocked by MFA, but at least one account was still accessed, likely through stolen web session cookies in a pass-the-cookie scenario that bypassed MFA checks. U.S. government guidance urged organizations to harden authentication and cloud access controls by enforcing universal MFA, using conditional access policies, reviewing logs for anomalous sign-ins, restricting external email forwarding, blocking legacy authentication, securing exposed remote access services, and improving user awareness to reduce credential theft and session hijacking risks.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
CISA released Analysis Report AR21-013A describing several successful attacks against organizations’ cloud services observed across multiple incident response engagements. The report detailed tactics including credential phishing, use of valid accounts, brute-force attempts, mailbox rule abuse, and likely pass-the-cookie activity, and provided mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
us-cert.cisa.gov
Open sourcecisa.gov
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.