A Discord User Hacked into a Company!

preview_player
Показать описание
Imagine being a large cloud computing company. You know, computer nerd wizardry. And then kaboom, a teenager with a room temperature IQ comes out of the woodwork to go wild.

Yep, a Discord scammer managed to hack a large company with a sophisticated technique. But was this hacking technique actually sophisticated? Or is Shadow, the company, lying to you?

SOCIALS
-----------------------------------------------------------------------------
Discord Server

Twitter

TIMESTAMPS
-----------------------------------------------------------------------------
00:00 - Advanced level hacking
01:16 - The scope of the breach
02:29 - How did the hacker do it?
04:44 - Preventable?
05:31 - Bankruptcy?
06:32 - How to protect yourself
Рекомендации по теме
Комментарии
Автор

Whenever you hear from a company that they've been a victim to a 'highly sophisticated' attack, it usually means that some dumb employee fell for a simple social engineering trick.

vinechetti
Автор

I'm shocked shadow didn't implode much sooner. That was by far one of the dumbest breaches imaginable. A 12 year old could of compromised that company.

dogeimpala
Автор

yea, the reality is, a surprisingly high amount of companies have very poor security, you'll be surprised how many companies genuinely use "123" type of passwords. But the fact that this was a Cloud virtual machine related company and not a regular restaurant or something it's outrageous

krizcold
Автор

Incredible! Imagine running a business providing virtual machines in the cloud, YET an employee decided to run a random EXE on their own production machine...

jd-raymaker
Автор

You'd just think Shadow the Hedgehog would have a stronger sense of internet safety. A shame, really

jack-the-threader
Автор

as someone who works in IT, youre right, we do in fact assume that everyone is an idiot
and people _still_ manage to do worse than i could ever have thought of

also, love the privacy and security tips!

gabbieblue
Автор

As soon as i read "social engineering" i immediately knew what happened. A friend recently fell for it lol

oxymore
Автор

I own a domain and I run a ton of email addresses - basically giving each service their unique one. And to be honest, it's shocking to see how many services are sharing data - willingly or unwillingly.

Toei-Rei
Автор

I would compare the security of these companies to swiss cheese, but that's insulting perfectly good cheese.

maiyannah
Автор

I wish they were more active with helping compromised accounts, poor people waiting weeks for a reponse

BlessedSeal
Автор

The 2021 bankruptcy story is well-known: They charged too cheap for the service at that time, but the processing load exceeded the benefits. They almost got ruined. They have been acquired after this bad move.
For the rest, it's exactly why I agreed with the tech company where I worked where they were **decent** protection measures. Not good, only decent, because I don't think this is at all common. The regular users only saw, "Our service is so bad. We can't do anything easily!" In a purely non-tech company, it isn't even possible to explain to someone why giving them my session password is a bad idea. "I'm not going to steal your account, you know?" That was a very competent colleague of mine, (I'm not being ironic, her job was different) looking at me like I was being stupid. Computers and good practices are something people view as something absolutely unimportant... "Until they get burned." To quote a famous social engineering book.

libalance
Автор

I've encountered more adults, generally boomer and older, that will trustingly download and run programs that lead to them infecting their PCs.

Wicked_Knight
Автор

I used to have shadow, and I stopped because not only is the product garbage (6 years old hardware), the support is beyond imaginable, like they take 5 days to send a mail saying "We'll get back to you". Never subscribe to it.

ewenlau
Автор

Holy frick, how gullible you have to be to have cloud-based company and not having InfoSec dept. Is this Shadow some fresh startup or something?

SilverCrow
Автор

I wrote a news post regarding this incident and I had to stop for 5 minutes because I couldn't stop laughing at the "sophisticated method". 😂

Marxally
Автор

Well then, I guess I'm glad I only ever put one of my throwaway emails into Shadow and no real info.

kmemz
Автор

Remember: don't shame individuals for falling for scams. It's ok to make fun of a large company for not having good IT but the practice of shaming idividuals makes people not want to talk about this kind of thing out of fear of being shamed and so we A.) don't get to learn as much from other people's mistakes because they won't want to share and B.) people won't ask questions they think are "stupid" and will try harder to just figure things out themself which is more likely to get them scammed. We need openness and that can't happen if we're shaming people for things that are only obvious in retrospect or with existing knowledge not everyone has.

pchris
Автор

its like discord is in a land field, and just keeps stepping on mines.

GaIaxyxvr
Автор

Bruh they literally straight download the malware, the only trickery was renaming a file and making a crappy website. I had no idea about this, keep up the great work!

HongKongZ
Автор

If Shadow is a french company then the GDPA is going to slap them hard for this kind of breach

hooting-ton