It will be interesting to see how the access was gained. I wonder how well this administrative system was protected. Did they have basic controls like: 1) Accessible via corporate VPN only (requiring 2fa) 2) Admin panel protected by 2fa plus necessary authentication+authorization controls 3) Audit trails Short of cooperative access (device handover), I could only see an outsider gaining access to the system due to po…
And the best part, support personnel often doesnt have MFA, because its outsourced to countries where smart phones with Authenticator apps are not as common to own for the regular person. I'm not joking.