TACTIC: CREDENTIAL ACCESS
Brute Force (T1110): real cases
MITRE Definition ↗ Adversaries use automated credential guessing or password spraying against authentication portals.
Key Facts
Technique ID
T1110
Credential Access
Mapped Cases
3
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1110.
- Tactical Phase: Credential Access.
- Substantiated in 3 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)
sentenced 2011-03-03
Primary Source Evidence Excerpt: Trial Transcript Day 5, Page 112
"He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems."
U.S. District Court for the Western District of Washington
View full case dossier →
Snowflake Enterprise Credential Stuffing & Customer Cloud Thefts
alleged 2024-05-23
Primary Source Evidence Excerpt: Snowflake & CrowdStrike Joint Forensic Investigation Statement
"Adversaries utilized custom automated tooling named FROSTBITE to systematically test credentials across hundreds of customer tenant URLs and generate presigned staging URLs."
U.S. Securities and Exchange Commission & FBI Cyber Division
View full case dossier →
Microsoft Corporate Executive Email Intrusion (Midnight Blizzard / SVR)
investigation 2024-01-19
Primary Source Evidence Excerpt: Microsoft Security Response Center (MSRC) Investigation Update
"Adversaries executed a slow, distributed password spray against a non-production legacy tenant account that did not enforce multi-factor authentication."
U.S. Securities and Exchange Commission & CISA Emergency Directive 24-02
View full case dossier →