How One Criminal Tried to Sell an MSP on the Dark Web

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress recounts a real-world incident where a cybercriminal (later identified as a disgruntled ex-employee) attempted to sell access to a compromised MSP's VPS control panel on the dark web for $600 BTC. The Huntress team, working through an MSP-ISAC Slack community with Datto and ConnectWise, directly engaged the attacker undercover on Wickr to extract enough details to identify and warn the victim MSP. Key takeaways include the importance of threat intel sharing between vendors, auditing admin accounts after employee departures, enforcing MFA, and avoiding exposed RDP. The attacker was later arrested in Atlanta and identified as a former employee of the victimized MSP with poor operational security.

11m read timeFrom huntress.com
Post cover image
Table of contents
The Latest Scoop as of February 10, 2020Original Post from February 4, 2020