PRIMARY SOURCE FORENSICS ARCHIVE

Cyberattack Facts & Forensics Archive

A permanent, chronological collection of verified real-world cyberattack facts, strange forensic discoveries, and courtroom precedents drawn from federal indictments, CISA technical alerts, and unsealed exhibits.

/
Showing 23 of 23 facts
Category:
2026-09-28 Malware Forensics
#fact-notpetya-ghana-power-outage

A Single Power Outage in Ghana Saved the World's Largest Shipping Line

When the NotPetya wiper obliterated all 150 Active Directory domain controllers across A.P. Moller-Maersk's global headquarters in minutes, the entire company was saved by a single offline domain controller in Ghana that survived solely because of a local blackout. Technicians physically flew the hard drive to London in a passenger seat to restore worldwide operations.

Source: Wired Forensic Investigation & Maersk Disclosures
2026-09-27 Social Engineering
#fact-mgm-10-minute-vishing

A 10-Minute Phone Call Brought Down the Las Vegas Strip

The catastrophic September 2023 breach that shut down MGM Resorts slot machines, digital room keys, and ATMs was not initiated by zero-day malware. Operatives from Scattered Spider looked up an employee on LinkedIn, called the Okta IT helpdesk pretending to be that employee, and convinced technicians to reset their MFA credentials in under 10 minutes.

2026-09-26 Heists & Extortion
#fact-bangladesh-bank-printer-jam

A Jammed Printer Saved $870 Million from North Korean Hackers

When North Korean Lazarus Group operatives issued 35 fraudulent SWIFT wire transfer orders totaling $951 million against the Bangladesh Central Bank, they were stopped from stealing the remaining $870 million because a local automated receipt printer on the 10th floor jammed and ran out of paper, alerting staff to anomalous transactions.

2026-09-25 Infrastructure
#fact-colonial-inactive-vpn-password

A Leaked Dark-Web Password Shut Down 45% of East Coast Fuel

The DarkSide ransomware attack that paralyzed the 5,500-mile Colonial Pipeline and triggered emergency declarations across 17 states was traced back to a single inactive employee password leaked on a dark-web paste. The legacy VPN portal lacked multifactor authentication, letting attackers walk straight into the billing network.

2026-09-24 Malware Forensics
#fact-wannacry-killswitch-domain

A $10.69 Domain Registration Stopped the Worst Ransomware Outbreak in History

In May 2017, the global WannaCry ransomware outbreak infected 300,000 computers in 150 countries within hours, paralyzing the UK National Health Service. 22-year-old researcher Marcus Hutchins discovered a bizarre hardcoded web address in the code and registered it for $10.69, accidentally activating an internal kill-switch that halted global propagation.

Stuxnet Physically Tore Centrifuges Apart While Showing Normal Displays

Stuxnet did not just shut down Iranian uranium centrifuges at Natanz; it secretly sped them up from their safe 1,064 Hz frequency to 1,410 Hz (causing physical rotor deformation and explosion) while recording normal operational sensor telemetry and playing it back on a loop to control room monitors so scientists thought everything was normal.

Source: Symantec Security Response Technical Dossier

A Staged Lovers' Quarrel Prevented Full-Disk Encryption

When the FBI arrested Silk Road mastermind Ross Ulbricht at the Glen Park Public Library in San Francisco, two undercover agents staged a loud, dramatic domestic argument right behind him. When Ulbricht turned around in shock, an agent snatched his unencrypted Samsung laptop from his hands before he could press a hotkey to encrypt his disk.

Source: Trial Testimony: U.S. v. Ulbricht (S.D.N.Y.)
2026-09-21 Malware Forensics
#fact-shamoon-hard-drive-shortage

Saudi Aramco Had to Buy Up the Global Supply of Hard Drives

In August 2012, Iranian state hackers deployed the Shamoon wiper against Saudi Aramco, wiping 35,000 computers simultaneously and replacing their boot screens with a burning American flag. To rebuild operations, Saudi Aramco executives flew to Taiwan and Southeast Asian factories to purchase every computer hard drive coming off production lines.

2026-09-20 Social Engineering
#fact-target-hvac-refrigeration-breach

40 Million Credit Cards Compromised via an Air Conditioning Vendor

The historic 2013 Target data breach that exposed 40 million debit and credit cards was not launched by hacking Target's servers directly. Hackers sent a phishing email to Fazio Mechanical Services, a small heating, ventilation, and air conditioning (HVAC) contractor in Pennsylvania, and used their electronic billing credentials to jump onto Target's corporate network.

Source: U.S. Senate Commerce Committee Investigation
2026-09-19 Social Engineering
#fact-twitter-teen-godmode-portal

A 17-Year-Old Used 'God Mode' to Hijack the President and Elon Musk

In July 2020, 17-year-old Graham Ivan Clark phoned Twitter employees claiming to be from corporate IT support, convincing them to enter their credentials on a phishing page. With access to Twitter's internal customer service tool (known internally as 'God Mode'), he hijacked verified accounts for Joe Biden, Barack Obama, and Elon Musk to promote a Bitcoin giveaway.

Russian Spies Used 'Golden SAML' to Read Federal Emails Undetected for 9 Months

Russian SVR operatives behind the SolarWinds breach did not just infiltrate networks; they stole Active Directory Federation Services (AD FS) private token-signing certificates to execute 'Golden SAML' attacks. This allowed them to mint their own cryptographic identity tokens and access federal Microsoft 365 cloud email without knowing any passwords or triggering MFA.

2026-09-17 Infrastructure
#fact-equifax-struts-patch-unapplied

A 66-Day Delay on a Free Security Patch Exposed 147 Million Americans

The Equifax breach that compromised the Social Security numbers of 147 million Americans occurred because a free security patch for Apache Struts (CVE-2017-5638) was released in March 2017, but Equifax's internal security scanner failed to flag vulnerable dispute portal servers. The servers remained unpatched for 66 days until Chinese PLA hackers extracted 265 separate databases.

Source: DOJ Indictment 1:20-cr-00071 & House Oversight Report
2026-09-16 Law & Precedent
#fact-capital-one-slack-boasting

A Cloud Hacker Was Caught Because She Posted Her Exploits on Public GitHub

Former AWS engineer Paige Thompson exploited an SSRF flaw on Capital One's cloud firewall to download 100 million credit card applications from 700 Amazon S3 buckets. Despite the sophisticated cloud exploit, she was apprehended within days because she boasted about the hack in a private Slack channel and published the exact extraction script on her public GitHub profile.

2026-09-15 Heists & Extortion
#fact-alphv-exit-scam-350-bitcoin

A Ransomware Boss Took a $22M Payout and Cheated His Own Hacker

When Change Healthcare paid a record 350 Bitcoin ($22 million) ransom in March 2024 to restore healthcare billing systems, the mastermind behind ALPHV/BlackCat kept the entire sum, locked out the affiliate operative who actually executed the intrusion, and posted a fake law enforcement takedown notice to fake his own disappearance.

Source: Blockchain Intelligence & Public Forum Disclosures
2026-09-14 Heists & Extortion
#fact-lockbit-secret-data-retention

LockBit Promised to Delete Stolen Files, But Secretly Kept Them All

Operation Cronos, the international police operation that took down LockBit in February 2024, seized backend servers revealing that despite charging victims millions of dollars for 'proof of destruction', LockBit never deleted the exfiltrated data. Law enforcement recovered petabytes of files that victims had paid ransoms to have destroyed.

Source: UK National Crime Agency Operation Cronos Release
2026-09-13 Law & Precedent
#fact-fin7-fake-security-company

A Cybercrime Syndicate Created a Real Cybersecurity Firm to Hire Unsuspecting Hackers

The Russian cybercrime syndicate FIN7 (Carbanak) established a front cybersecurity company named 'Combi Security' with legitimate commercial offices in Russia and Ukraine. They recruited university graduates, software engineers, and translators who believed they were doing corporate penetration testing, while actually weaponizing malware that stole millions from Chipotle and Arby's.

Olympic Destroyer Took Down the Winter Games Minutes Before the Opening Ceremony

Minutes before the 2018 Winter Olympics opening ceremony in Pyeongchang, South Korea, Russian GRU hackers deployed the Olympic Destroyer wiper. The attack disabled Wi-Fi across the stadium, shut down broadcast televisions, and disabled the RFID ticketing turnstiles, forcing attendees to queue in freezing temperatures in retaliation for Russian athletes being banned for doping.

2026-09-11 Infrastructure
#fact-volt-typhoon-5-year-dormancy

Volt Typhoon Stayed Dormant in Critical Utilities for Over 5 Years Without Malware

Chinese state-sponsored group Volt Typhoon maintained access inside US municipal water systems, port terminals, and energy grids for up to five years without ever being flagged by antivirus software. They deployed zero custom malware binaries, relying entirely on Living-off-the-Land (LotL) native Windows administrative commands like wmic and net.exe.

2026-09-10 Infrastructure
#fact-kaseya-revil-fourth-of-july

REvil Specifically Timed Their Attack for the Fourth of July Long Weekend

In July 2021, ransomware syndicate REvil timed their supply-chain attack on Kaseya VSA management servers to deploy exactly on the Friday afternoon preceding the American Fourth of July weekend. Because IT and security teams were on holiday leave, the ransomware encrypted over 1,500 downstream businesses worldwide before anyone could respond.

21.5 Million Deep-Dive Background Investigation Records Were Stolen from OPM

The 2015 Office of Personnel Management (OPM) breach resulted in Chinese state actors exfiltrating the 127-page Standard Form 86 (SF-86) dossiers of 21.5 million federal employees. These files contained intimate admissions regarding financial bankruptcy, substance abuse, psychiatric treatment, and foreign family ties, creating a permanent counterintelligence dossier on US officials.

Source: House Committee on Oversight and Government Reform Investigation

A Single Citrix Server Without MFA Paralyzed Half of American Healthcare

When UnitedHealth Group CEO Andrew Witty testified before Congress regarding the $3B+ Change Healthcare cyber catastrophe, he admitted the initial point of intrusion was a single remote access Citrix portal that was not upgraded with multi-factor authentication. Threat actors used harvested employee credentials to walk into the core network and hold half the nation's pharmacy transactions hostage.

Source: House Energy and Commerce Committee Hearing Testimony
2026-09-07 Heists & Extortion
#fact-snowflake-infostealer-logs

Stolen Credentials from Personal PCs Compromised 165+ Enterprise Cloud Warehouses

The massive 2024 campaign that compromised customer databases at Ticketmaster, Santander Bank, and Advance Auto Parts did not involve any vulnerability in Snowflake. Instead, threat actors utilized credentials harvested years earlier by infostealer Trojans on contractors' unmanaged personal computers to log into enterprise accounts that lacked MFA and network IP allowlisting.

Russian Spies Infiltrated Microsoft Executives Through an Abandoned Test Account

Russian SVR operatives (Midnight Blizzard) gained access to the corporate mailboxes of Microsoft senior leadership and cybersecurity executives not by exploiting Windows zero-days, but by password spraying an abandoned, non-production test tenant account that lacked multi-factor authentication and retained excessive tenant-wide OAuth application permissions.