Get a free audit

Field Notes / Dossier 014

The login that already worked: how one valid password ends a small firm

We replay a real-shape engagement against a London business. No exotic exploit, no broken locks. One credential that still worked, and a quiet walk through everything it reached.

Author
Red Team Partners
Read
8 MIN READ
Filed
22 June 2026

01 The way in

They left no broken locks. No alarm tripped at 02:14. The only trace was a session token, minted three weeks earlier from a laptop nobody had reported missing. By the time the audit ran, the way in had already been mapped, walked and quietly closed behind them.

The credential came from a reused password, exposed in an unrelated breach and never changed. Most intrusions start this way rather than with a fresh exploit Verizon DBIR 2024 . The account belonged to a junior member of staff in London, with no special privileges. That did not matter. A valid login is a valid login, and the front door does not ask why you are early.

RECON 14:03 An exposed remote-desktop session observed from an unmanaged host in London.
Inbound session observed from an unmanaged host in London. No alert fired, because nothing looked broken.

02 What we found

Once inside, the picture changed fast. The same password worked on the shared finance inbox. From there we read the supplier correspondence, learned the payment cadence, and found a standing instruction that nobody had locked down. None of it required a second exploit. It required patience and a borrowed uniform.

This is the part a scan cannot see. A scan reports that a port is open or a patch is missing. It does not follow a working login from one system to the next and tell you where the money lives. That is the attacker's question, and it is the one we answer.

03 The blast radius

Blast radius is the honest measure of a breach. Not how clever the entry was, but how far the access carried once someone was in. For this firm, one junior credential reached the funds, the supplier trust and the means to move money quietly. The gap between getting in and being noticed is usually measured in days, not minutes IBM 2024 .

04 The fix

None of this needed a large budget to close. It needed someone to find the way in first and shut it. After the engagement, the firm cleared every gap we walked through, in under two weeks and without new headcount. Enterprise-grade cybersecurity, within reach.

Remediation Log
  • Reused password reset and two-factor turned on for every account
  • Shared finance inbox split into named, per-staff logins
  • Exposed remote desktop closed and placed behind a VPN
  • Standing payment instruction locked behind a second approver

References

Sources

  1. Verizon. 2024 Data Breach Investigations Report (DBIR). Verizon Business, 2024. verizon.com
  2. IBM Security. Cost of a Data Breach Report 2024. IBM Corporation, 2024. ibm.com
  3. MITRE. ATT&CK Enterprise Matrix, version 15. The MITRE Corporation, 2024. attack.mitre.org