Threat actors gained initial access to a target environment by compromising a third-party IT services provider and abusing trusted management tools. By masking malicious activity as routine administrative tasks, the attackers maintained a foothold for over 100 days to harvest cleartext credentials. This method highlights the significant risk that supply chain vulnerabilities pose to the security of financial networks.

Relevant URL: https://www.microsoft.com/en-us/security/blog/2026/05/12/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-through-third-party-compromise/