Key facts
- Organisation
- A Singapore professional services firm
- Threat
- Ransomware intrusion with data theft and extortion
- Initial access
- A valid password used over a remote-access VPN that required no second verification step
- Impact
- Full network compromise; the entire stored credential base exposed; sensitive business data within reach for three months
- Core issue
- One password stood between the attacker and everything, with no multi-factor check and a flat, barely-logged network behind it
What this case shows
- A password on its own is a single point of failure. Without a second check, one login can equal total access.
- Backups and virtualisation hosts are the first things attackers go for, not safe ground to fall back on.
- Thin logging turns a contained incident into a reportable breach, because you cannot prove what did or did not leave.
Worried an attacker may already hold a working login into your network? Start with a Compromise Assessment, or keep response on standby with IR-1.
What this would have cost with Blackpanda IR-1 in place
| ODIR | IR-1 | |
|---|---|---|
| Type of engagement | On-demand incident response | Yearly subscription |
| Hours covered | 45 hours | Unlimited* |
| Pricing1 | USD $22,500 | USD $2,250 |
* Unlimited for one incident per year
1 Ad-hoc incident response pricing based on average market rates, from USD 500 per hour. Blackpanda IR-1 subscription pricing based on no. of endpoints, costing approx. 10x less than ad-hoc and retainer-based incident response. All figures are illustrative only, for guidance and marketing purposes and not to be relied upon by the reader. Actual incident response costs vary by scope, complexity, and provider.
CHALLENGE
The firm is a Singapore professional services practice that holds exactly the kind of material attackers want: financial records, client files, and the private business of the people it advises. Like many firms its size, it handed the day-to-day running of its systems to an outside IT provider and trusted that the arrangement was working.
It was not. In January 2026 an attacker signed in to the firm's remote-access VPN using a valid administrator password. Nothing was exploited and nothing was forced. The VPN asked for a password and nothing else, no second check of any kind, and no rule existed to lock an account after repeated failures. How the password was obtained could not be reconstructed, because the network equipment kept its logs for only seven days and the relevant week was long gone before anyone came looking. A remote-access VPN that asks only for a password is a recurring entry point in ransomware intrusions across the region, and this one behaved true to form.
That single login was enough to reach everything. The internal network was flat and uninspected, so one connected session could travel to every server the firm owned. For roughly three months the attacker moved through the environment unnoticed. The firm found out the way too many organisations do, not from an alert, but when a ransomware group posted its name on a public leak site in April 2026.
SOLUTION
1. Take back control of every credential
Blackpanda forced a reset across every account in the domain, reset the master administrator and the underlying key-distribution account twice to close a known re-use trick, and cut off active sessions so a stolen token could not be replayed. The backup software had been configured to run as the top administrator, quietly storing that password where the attacker could take it; that credential was pulled out and rotated as well.
2. Evict the attacker's hidden footholds
The attacker had left several ways back in. Blackpanda removed the backdoor accounts, the commercial remote-control tool planted on the virtualisation host, the deep system-level implants, and a self-healing component built to reinstall itself within seconds of removal. The staged data-theft tooling was pulled off the affected servers at the same time.
3. Rebuild what could no longer be trusted
Some systems were too deeply compromised to clean. The attacker had reached the backup and virtualisation servers directly, the same systems targeted in other VPN-driven ransomware cases, so neither could be wiped in place and trusted afterwards. Blackpanda rebuilt the directory server and the virtualisation host from known-clean media and validated them before they went back into service.
4. Close the door and keep it closed
Finally, the perimeter and the identity layer were hardened together. Multi-factor authentication was turned on for all remote access, the Remote Desktop ports exposed straight to the internet were removed, and the VPN was segmented and restricted so one session could no longer reach the whole network. Firewall management was locked down, endpoint security was restored to a tamper-protected state on every server, and the firm's cloud email and identity platform was tightened, from conditional access to email authentication to switching off legacy sign-in methods and silent mail forwarding.
RESULTS
1. A full timeline, built from what survived
Working around the missing logs, Blackpanda reconstructed roughly three months of attacker activity from the evidence that remained, establishing when access began and how far it spread.
2. The true scope, made plain
Every password in the firm's directory had to be treated as compromised, and sensitive financial, HR, and client folders had been within the attacker's reach the entire time.
3. A defensible breach position
A data-theft tool sat ready on the network while the traffic logs that would have shown what left were already gone, so data loss had to be treated as realistic. Blackpanda gave the firm the clear, evidence-based footing it needed for its regulatory notification, rather than a guess.
4. A restored, trusted environment
Clean rebuilds, enforced multi-factor authentication, and closed exposures returned the firm to an environment it could actually rely on.
One detail anchored the whole investigation. A single compromised password had opened the entire network, and everything that followed flowed from it. The technology that failed was ordinary. What was missing was ordinary too: a second check on every login, a network that did not treat one session as fully trusted, and logging good enough to answer the only question that matters afterwards, which is what actually left. Those are decisions made in quiet times, long before an incident, and they are the ones that decide how bad it gets.
FREQUENTLY ASKED QUESTIONS
1. How did attackers get in without any malware or hacking?
They logged in. Using a valid administrator password over a VPN that asked for nothing else, they walked through the front door the same way an employee would. No software flaw was exploited, which is exactly why nothing flagged it as an attack.
2. Isn't a VPN supposed to keep intruders out?
A VPN controls who reaches the door, but it does not decide what they can touch once inside. Without a second identity check and without internal segmentation, a single stolen password let one session roam the entire network. This pattern turns up again and again; you can see it play out in a similar SSL VPN intrusion at an industrial manufacturer.
3. If the ransomware itself was never seen encrypting files, why treat this as a data breach?
Because the attacker staged a working data-theft tool and held the highest level of access for three months, while the logs that would have proved what left the network were no longer available. When you cannot rule data loss out, responsible practice, and often the law, is to treat it as a real possibility and notify accordingly.
4. Why rebuild the servers instead of just cleaning them?
The attacker planted controls that operate below the level ordinary security tools can see, including a component that repaired itself when removed. Once a system has been controlled that deeply, you can no longer trust anything running on it. Rebuilding from clean media is the only way to be certain the attacker is gone.
5. What one change would most likely have stopped this?
Multi-factor authentication on remote access. A stolen password alone would not have been enough to get in, and the intrusion would have stalled at the very first step. It is among the cheapest and most effective controls a firm can put in place; a Compromise Assessment will show where the gaps are today.
6. We think a login may already be compromised. What should we do first?
Act immediately, because the first hours shape everything that follows. Preserve your logs before they age out, avoid tipping off the intruder, and bring in incident responders who can contain the account without destroying the evidence. Keeping response capability on standby through IR-1 or emergency incident response means that first call is already made.
WHAT THIS MEANS FOR YOUR ORGANISATION
Nothing about this case is exotic. An ordinary firm, ordinary software, and one working password added up to a full compromise, and it did so because a handful of routine decisions had gone unmade. No second check on remote logins. A flat internal network that trusted any connected session. Logging so thin the firm could not reconstruct its own breach. Each gap is unremarkable on its own; together they are how most intrusions succeed.
The lesson worth carrying is that the fixes are known and affordable, and they belong in place before an incident rather than after one. Multi-factor authentication on every remote entry point, real segmentation between systems, and logging you can actually investigate would each have blunted this attack. If it has been a while since anyone tested whether a single stolen password could open your network, a Compromise Assessment answers that question directly, and keeping response on retainer through IR-1 means help is already in place when the answer is uncomfortable.
ABOUT BLACKPANDA
Blackpanda is a Lloyd's of London–accredited insurance coverholder and Asia's leading local cyber incident response firm, delivering end-to-end digital emergency support across the region. We are pioneering the A2I (Assurance-to-Insurance) model in cybersecurity — uniting preparation, response, and insurance into a seamless pathway that minimises financial and operational impact from cyber attack. Through expert consulting services, response assurance subscriptions, and innovative cyber insurance, we help organisations get ready, respond, and recover from cyber attacks — all delivered by local specialists working in concert.
Our mission is clear: to bring complete cyber peace of mind to every organisation in Asia, from the first moment of breach through full recovery and beyond.





