Tim was under-appreciated, board, anxious, and job-hunting. He’d been working for a well know coffee and treats company for several years. Although he’d survived the first round of lay-offs, more were coming, and soon. He thought he was a pretty good senior engineer, holding a bachelors in computer science and sporting over a decade of experience. Even so, the company decided it was going to outsource most of its technology department as it prepared to adopt AI agents in permanent replacement of human headcount.
In the transition of migrating workloads to the recently contracted third-party vendor, Tim found he had little to do except browse LinkedIn for career prospects, and obsessively search his email for any signs of hope of retaining his current position. It was while checking and rechecking for the anticipated, but dreaded announcement, of another cut to his team’s already thin head-count, that he noticed an unread email in his trash.
Confluence, the companies central digital workspace and knowledge management system, had sent him a notice that he’d been mentioned on a page titled “Third-Quarter Awards.” This was it! The hope he’d been anxious seeking had materialized in a moment. Without hesitation Tim clicked on the link, which opened a sign-in page. To his great disappointment, after submitting his credentials the screen returned an error message indicating the page no longer existed.
While Tim stepped away from his desk to nurse his frustrations, the hackers celebrated. They’d crafted and timed the pretext perfectly. Using an aged typo-squatted domain, and phish designed to cause cognitive-compression, they easily bypassed the software and security controls meant to stop their attack. With Tim’s credentials, and a previously identified gap in implementation of the company policy for multi-factor authentication, it was simple to gain access to the real confluence workspace. A search of the term “password” yielded more gaps in the corporate cyber-defense strategy. In plain text for the hackers taking, were clear admin account names and authentication codes. With in hours they’d moved laterally across systems, elevated privileges, and achieved domain admin.

While Tim is a prototype, and not a real senior engineer, this narrative was reflective of real corporate sponsored hacks, aka red-team exercises. The storied attack isn’t unique to the fictionalized company either. Red-teams across major corporations have proven time and again that despite abundant software solutions, awareness training, and mature cybersecurity policies, phishing is still the easiest and most effective avenue for gaining access to corporate infrastructure.
Multi-factor authentication is helpful for preventing credential stuffing, password spraying, and brute-force logins, but the tactics to bypass second factors of authentication are as simple as manipulating the humans who control or implement the authentications. For example, if you’ve applied text messages as your second factor of authentication, a hacker only needs to convince you to give the code to them. Alternatively, they can convince your cell phone carrier they are you, thereby taking over the phone number and authentication all together. This tactic is called sim-swapping.
Similarly, Virtual Private Networks elevate organizational cybersecurity by encrypting traffic, and limiting access, as well as masking technical vulnerabilities from outside observation. However, an authenticated user on the VPN renders those controls useless. Storing plain text passwords inside word documents, text files, and shared drives is a known common problem. This is why the standard recommendation is to use a password manager. However, use of password managers introduces another attack surface to manage, and additional exposure for the companies that adopt them.
In 2022, for example, an industry leading password management company, “LastPass,” was breached. Customers of this service had their account information exposed broadly which included email addresses, billing details, phone numbers, IP addresses, and even the passwords they were trying to secure with this service. Several major businesses and institutional customers were forced to react quickly, rotating credentials across complex tech stacks. Those who were slow in responding we’re quick picked off by financially motivated threat actors in ransomware exploits, crypto thefts, and other schemes. This incident led to about $1.7 billion in known losses including cryptocurrency thefts and impacted 1.6 million users in the UK alone.
So what does this mean for small businesses? If major corporations can’t even get cybersecurity right, what hope does a SMB owner have? There is good news for the entrepreneur, start-up, mom-n-pop shop, and even mid-sized organizations. In the case of cybersecurity, size is to the benefit of the little guy.
Major corporations have major digital footprints. In other words, the bigger the company, the bigger the exposure, and the more uncontrollable variables which include third-party suppliers, dependencies in supply chains, and employees with varying levels of job-satisfaction, and awareness or suspicion of would-be-corporate threats.
Small business should use their size to their advantage. Yes, opt into multi-factor authentication, avoiding storing plain text passwords digitally, and use a VPN when managing critical systems. However, the most effective tactic any business can employ to elevate their cybersecurity posture is to first understand their digital exposure, and to be intentional about how that information is treated.
For example, you know that you’ve shared your address, phone number, upcoming events, and even personal information relevant to the business you built. Knowing that information is freely available, treat it like it’s compromised. Running red-team styled exercises with your employees, using this exposed information is a great way to build trust and identify mitigative tactics that are unique to your situation. Using a data removal service like DeleteMe, and thinking about how the information your share openly on social-media, in marketing, or on your website could be used to impersonate, authenticate, or manipulate you, or those who have trusted access, is also helpful.
Countervail offers comprehensive cybersecurity and digital exposure reviews, enterprise-grade, actionable intelligence reports, and customized red-team workshops for small and mid-sized organizations. Complete the contact form below or email contact@countervailintelligence.com to inquire about frustrating would be scammers, fraudsters, and other cybercriminals targeting your business today.

Leave a Reply