Organization hit by network compromise linked to Velvet Ant
Incident
Updated: 13.06.2026 17:06
· First: 13.06.2026 17:06
· 📰 1 src / 1 articles
· H score: 35
A target organization suffered a 10-year authentication stack compromise that exposed administrative activity inside an isolated critical infrastructure network. The intrusion was linked to Velvet Ant and Operation Highland, and it began in 2016 after access through internet-facing systems. Attackers then preserved access by modifying PAM and OpenSSH components to steal credentials and observe every login and command.