Huntress publicly disclosed an unauthorized access incident in their QA environment where an attacker brute-forced an ephemeral Windows VM using weak credentials (Administrator/abc123!!!). No customer data, billing info, production systems, or source code was compromised due to proper network segmentation between QA and production AWS environments. The post details the full incident timeline, forensic investigation steps, remediation actions (switching to SSH key auth, disabling RDP, fixing VM orphaning bug, tightening CircleCI/AWS permissions), and guidance from their legal and cyber insurance teams. Huntress chose to disclose publicly despite no legal obligation, advocating for greater transparency and incident disclosure normalization across the industry.

10m read timeFrom huntress.com
Post cover image
Table of contents
First Things First: Do I Need To Be Concerned?Why Are We Disclosing This?So What Happened?What Did We Do?What New Processes Have We Implemented?Segmentation MattersGuidance From Our Legal TeamGuidance From Our Cyber Insurance TeamFinal Words