Threat actors gained initial access to a target environment by compromising a third-party IT services provider and abusing trusted management tools. By masking malicious activity as routine administrative tasks, the attackers maintained a foothold for over 100 days to harvest cleartext credentials. This method highlights the significant risk that supply chain vulnerabilities pose to the security of financial networks.