Field Notes / Dossier 014
The login that already worked: how one valid password ends a small firm
We replay a real-shape engagement against a London business. No exotic exploit, no broken locks. One credential that still worked, and a quiet walk through everything it reached.
01 The way in
They left no broken locks. No alarm tripped at 02:14. The only trace was a session token, minted three weeks earlier from a laptop nobody had reported missing. By the time the audit ran, the way in had already been mapped, walked and quietly closed behind them.
The credential came from a reused password, exposed in an unrelated breach and never changed. Most intrusions start this way rather than with a fresh exploit Verizon DBIR 2024 . The account belonged to a junior member of staff in London, with no special privileges. That did not matter. A valid login is a valid login, and the front door does not ask why you are early.
02 What we found
Once inside, the picture changed fast. The same password worked on the shared finance inbox. From there we read the supplier correspondence, learned the payment cadence, and found a standing instruction that nobody had locked down. None of it required a second exploit. It required patience and a borrowed uniform.
This is the part a scan cannot see. A scan reports that a port is open or a patch is missing. It does not follow a working login from one system to the next and tell you where the money lives. That is the attacker's question, and it is the one we answer.
03 The blast radius
Blast radius is the honest measure of a breach. Not how clever the entry was, but how far the access carried once someone was in. For this firm, one junior credential reached the funds, the supplier trust and the means to move money quietly. The gap between getting in and being noticed is usually measured in days, not minutes IBM 2024 .
04 The fix
None of this needed a large budget to close. It needed someone to find the way in first and shut it. After the engagement, the firm cleared every gap we walked through, in under two weeks and without new headcount. Enterprise-grade cybersecurity, within reach.
- Reused password reset and two-factor turned on for every account
- Shared finance inbox split into named, per-staff logins
- Exposed remote desktop closed and placed behind a VPN
- Standing payment instruction locked behind a second approver
References
Sources
- Verizon. 2024 Data Breach Investigations Report (DBIR). Verizon Business, 2024. verizon.com
- IBM Security. Cost of a Data Breach Report 2024. IBM Corporation, 2024. ibm.com
- MITRE. ATT&CK Enterprise Matrix, version 15. The MITRE Corporation, 2024. attack.mitre.org