My Authors
Read all threads
SANS infosec training org suffers data breach after phishing attack - @LawrenceAbrams
bleepingcomputer.com/news/security/…
In a 'Data Incident' incident notification, SANS states they discovered that one of their employees' email accounts was compromised during a phishing attack.
As part of this attack, a malicous Office 365 addon (most likely an Oauth app) was installed and a rule was created to forward incoming mail to an unknown external email address.

For more information about malicious Office 365 Oauth apps:
bleepingcomputer.com/news/security/…
As part of this compromise, a total of 513 emails were forwarded, containing a total of approximately 28,000 records of personal information (PII).
This information includes email addresses, full names, phone numbers, work title, company names, and physical addresses. It did not contain any financial info or passwords.
SANS' digital forensics instructors will be performing the investigation, and at the end, will host a webinar to share their findings with the rest of the cybersecurity community. Should be an interesting learning experience for many.
SANS notification can be found here:
sans.org/dataincident20…
Missing some Tweet in this thread? You can try to force a refresh.

Keep Current with BleepingComputer

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!