Case study banner: 4,000 Files Taken from Malaysian Professional Services Firm Within 30 Minutes. Type: Blackpanda IR-1 Activation.

Attacker Empties Almost 4,000 Files from Malaysian Professional Services Firm in Half an Hour

LAST EDITED:
PUBLISHED:
August 6, 2026

No malware, no encryption, no mailbox access. One correctly entered password was enough to strip a cloud drive bare and turn an employee's own files into a threat.

Key facts

Organisation
Malaysian professional services firm
Threat
Account takeover leading to mass file theft, a Qilin extortion note, and destruction of stored work
Initial access
A stolen password entered correctly at sign-in, with no multi-factor authentication enforced anywhere in the tenant
Impact
Almost 4,000 files taken in less than half an hour; over 150 folders and files deleted; the ransom note pushed to roughly 10 colleagues
Core issue
Identity guarded by a password alone, with legacy authentication reachable and no risk-based detection to catch an impossible-travel login

What this case shows

  • A password with no second factor is a single point of failure, and attackers no longer need malware on a managed device to find one.
  • Partial containment invites the attacker back. Revoking tokens without resetting the password left the door open for another day.
  • Cloud file storage is now the target, not just the route. Nothing was encrypted here, yet the firm still lost its work and still faced a disclosure question.
  • Permissive default sharing turns one compromised account into a delivery mechanism aimed at everybody else.

Blackpanda's digital forensics team settled the entry point from the logs alone, and IR-1 put the response on the clock from the first call.

What this would have cost without Blackpanda IR-1 in place

ODIRIR-1
Type of engagementOn-demand incident responseYearly subscription
Hours covered35 hoursUnlimited*
Pricing1USD $17,500USD $1,750

* Unlimited for one incident per year

1 Ad-hoc incident response pricing based on average market rates, from USD 500 per hour. Blackpanda IR-1 subscription pricing based on no. of endpoints, costing approx. 10x less than ad-hoc and retainer-based incident response. All figures are illustrative only, for guidance and marketing purposes and not to be relied upon by the reader. Actual incident response costs vary by scope, complexity, and provider.

CHALLENGE

Operating almost entirely in the cloud, the firm manages corporate services for a large group of companies. Shared internal document sites and personal cloud storage house tender files, design drawings, and project documents. They are all accessible from anywhere provided one has the correct password and, ultimately, that proved to be the root of the entire issue.

Roughly a week before the breach occurred, a single employee account was targeted from a European host with nearly 300 unsuccessful sign-in attempts using a legacy authentication protocol, ceasing only after the account was automatically locked. Although this initial password spray was unsuccessful, in hindsight it served as a clear indicator that somebody had the employee's address, and that the tenant's oldest access route remained exposed.

In June 2026, someone signed in from a European internet address using the correct password. No second factor was requested, because none had been enforced. Within a minute the attacker began downloading, and in less than half an hour pulled almost 4,000 files out of the employee's storage using the platform's own bulk archive-download function. Then they moved sideways, reaching more than five colleagues' storage sites under the same hijacked session, taking files from three of them.

The firm's IT team spotted the intrusion the next morning and acted, revoking the account's active sessions and stripping its registered authentication methods. They did not reset the password. That evening the attacker signed back in, uploaded a Qilin ransom note into the employee's document folder, broke the folder's inherited permissions, and generated several sharing links that delivered the note to roughly 10 colleagues. Minutes later the deletions started. Only when the platform's own bulk-deletion alert fired did anyone understand the scale of what was happening.

SOLUTION

1. Settle the entry point before anything else

Most account takeovers end with an unanswerable question about how the attacker got in. A stolen password means resetting credentials and enforcing a second factor. A stolen session token means the second factor was already defeated and the fix is different. Blackpanda pulled the detailed authentication records for the intruding sessions and found a single factor, a correctly entered password, with no second-factor detail attached. Every subsequent step in the session showed single sign-on continuation from that one login, which confirmed a fresh password authentication rather than a replayed cookie.

2. Map the full blast radius across storage, sharing and mail

Reconstructing the intrusion from the unified audit log gave an exact operation-by-operation account of what the attacker touched. That established the download volume, the upload of the ransom note, the permission changes, the sharing links, and the deletions, each tied to the intruding address. It also established the lateral movement into colleagues' storage, distinguishing the sites merely browsed from the three actually stolen from.

Mail deserved separate treatment. The account was labelled a business email compromise when the case opened, so Blackpanda queried every mail-access record for the mailbox and cross-referenced them against the attacker's addresses. Not one matched.

3. Close the account properly, then confirm the eviction held

The first containment pass had failed because it treated the symptom, not the credential. Blackpanda directed a complete close-out: tokens revoked again, multi-factor authentication switched on, the password reset, and authentication methods re-registered by the account holder. Verification then mattered as much as the action. Neither attacker address appears anywhere in the logs after the reset, which is what turns “we think it's contained” into a defensible statement.

4. Chase the credential off the managed estate, and measure the tenant

Both of the account holder's laptops went through full forensic triage across a 30-day window either side of the intrusion. Almost 3,000 execution and installation records returned zero matches against known credential-theft malware families, and the browser histories showed no phishing page, no adversary-in-the-middle proxy, and no rogue application consent. The managed devices were clean, which pointed the capture somewhere the firm could not see.

Two exposures surfaced instead. The corporate password sat saved in the browser password store on both machines. Separately, the employee's personal webmail identity appeared reused across dozens of consumer sites, well outside anything the firm controls. Blackpanda then ran the tenant against a published cloud configuration baseline to establish which settings had allowed the intrusion to succeed and to run unnoticed for two days.

RESULTS

1. Root cause established as a single factor, not a defeated one

The intrusion came down to a password with nothing behind it, ruling out session hijacking and, with it, an expensive and unnecessary rebuild of the firm's authentication stack.

2. Scope of theft and destruction fixed precisely

Blackpanda quantified what left the tenant and what was destroyed, identified every colleague whose storage the attacker reached, and confirmed the deleted material was still recoverable from retention. That gave the firm a defensible basis for the data leak assessment and the notifications that followed.

3. Mailbox cleared as a confirmed negative

No mail was read, none was sent from the attacker's addresses, and no forwarding rule or delegation was created, which narrowed the disclosure exposure to stored files alone.

4. Managed devices cleared and the exposure relocated

Both laptops came back clean, moving the credential-capture question off the corporate estate and onto the saved browser password and the reused personal identity, where the firm could act on both.

5. Configuration causes named and ranked

The baseline scan failed more than 20 mandatory controls out of nearly 70 assessed, and Blackpanda grouped them so the firm could fix the three that caused this incident before touching the rest.

Every one of those three groups is a setting, not a product. Multi-factor authentication enforced tenant-wide, legacy authentication switched off, and default file sharing set to view-only would each have broken this attack at a different point, and none of them requires new spending. What the firm lacked, and what the scan quantified, was any risk-based detection tier to score a login that arrived from Europe against an access history that had never once left Malaysia. Around 20 administrator accounts also sat provisioned as hybrid rather than cloud-only, with no just-in-time privileged access. The attacker never pivoted to one. Had they tried, nothing would have slowed them down.

FREQUENTLY ASKED QUESTIONS

1. Was this actually a ransomware attack?

No, and the distinction matters commercially. Nothing was encrypted and no decryption key was ever on offer. The attacker stole files, planted a note bearing a known ransomware group's name, deleted the victim's work, and relied on the name alone to apply pressure. Extortion without encryption is now common enough that a ransom note should never be taken as proof of what actually happened to your data.

2. We have multi-factor authentication. Are we covered?

Only if it is enforced everywhere, including on legacy protocols, and only if it is a form attackers cannot phish. This firm had the capability available and switched on for nobody, which is a configuration state that looks identical to full protection on a licence summary. Attackers also routinely proxy weaker second factors in real time, as happened in our MFA bypass investigation at a Singapore IT services firm.

3. How did the attacker get the password if the laptops were clean?

The logs could not answer that, and no honest report will claim otherwise. Forensic triage excluded the managed devices, which leaves an unmanaged personal device, a third-party breach where the same password had been reused, or phishing conducted somewhere off the corporate estate. The saved corporate password in the browser and the heavily reused personal webmail identity are both live exposures worth closing regardless of which one it was.

4. Why did the first containment attempt fail?

Revoking active sessions and removing registered authentication methods deals with the access the attacker currently holds. It does nothing about the credential they will use next time. Because the password stayed valid and no second factor was enforced, the attacker simply logged in again the following evening. Containment is only complete once the credential itself is dead.

5. Can deleted cloud files be recovered?

Often, but the window is finite and it is shorter than most people assume. In this case the deleted folders were still sitting in retention when Blackpanda reached them, so recovery was possible. Retention periods vary by platform and licence tier, which makes recovery one of the first things to check rather than something to get to after the investigation.

6. What should we do first if we think an account has been taken over?

Reset the password, revoke every active session, and enforce a second factor, in that order and without waiting for the investigation to finish. Then preserve the logs before they age out, because sign-in and audit records have retention limits that will quietly destroy your ability to establish what happened. If you are unsure of the scope, report the incident and let a responder scope it while you contain.

WHAT THIS MEANS FOR YOUR ORGANISATION

The uncomfortable part of this case is how little the attacker needed. No malware, no exploit, no infrastructure beyond a browser and a hosting provider in another hemisphere. One valid password bought almost 4,000 files in half an hour, and the only reason the firm found out at all is that the attacker chose to be noisy on the second night. An intruder content to download quietly and leave would still be an open question today, which is the scenario worth planning for.

Two changes would have stopped this, and neither is a purchase. Enforce a second factor on every account and every protocol, then set default sharing to view-only so that one compromised mailbox cannot broadcast to the rest of the company. What no configuration can compress is the time between the alert firing and somebody competent reading the logs, and that gap is where a two-day intrusion turns into a two-week one. IR-1 exists to close it, putting a responder on the case from the first call rather than the first purchase order.

ABOUT BLACKPANDA

Blackpanda is a Lloyd's of London–accredited insurance coverholder and Asia's leading local cyber incident response firm, delivering end-to-end digital emergency support across the region. We are pioneering the A2I (Assurance-to-Insurance) model in cybersecurity — uniting preparation, response, and insurance into a seamless pathway that minimises financial and operational impact from cyber attack. Through expert consulting services, response assurance subscriptions, and innovative cyber insurance, we help organisations get ready, respond, and recover from cyber attacks — all delivered by local specialists working in concert.

Our mission is clear: to bring complete cyber peace of mind to every organisation in Asia, from the first moment of breach through full recovery and beyond.