Infostealer Breach Exploits Lack of MFA in 50 Enterprises
Summary
Hide ▲
Show ▼
A threat actor, Zestix (aka Sentap), exploited unsecured cloud file-sharing services to steal and auction sensitive data from 50 global organizations. The breach occurred due to the absence of multi-factor authentication (MFA), allowing Zestix to access accounts using credentials obtained from infostealer logs. The stolen data included corporate secrets, customer information, and military IP, with some credentials harvested years before the breach. The actor is linked to Russian and Iranian cybercrime groups and operates as an initial access broker (IAB).
Timeline
-
07.01.2026 11:45 1 articles · 23h ago
Zestix Exploits Infostealer Logs to Breach 50 Enterprises
Zestix (Sentap) accessed and exfiltrated sensitive data from 50 global organizations by exploiting unsecured cloud file-sharing services. The breach occurred due to the absence of multi-factor authentication (MFA), allowing the actor to use credentials obtained from infostealer logs. The stolen data included corporate secrets, customer information, and military IP, with some credentials harvested years before the breach. The actor is linked to Russian and Iranian cybercrime groups and operates as an initial access broker (IAB).
Show sources
- MFA Failure Enables Infostealer Breach At 50 Enterprises — www.infosecurity-magazine.com — 07.01.2026 11:45
Information Snippets
-
Zestix (Sentap) accessed cloud file-sharing services ShareFile, Nextcloud, and OwnCloud without MFA.
First reported: 07.01.2026 11:451 source, 1 articleShow sources
- MFA Failure Enables Infostealer Breach At 50 Enterprises — www.infosecurity-magazine.com — 07.01.2026 11:45
-
Credentials were obtained from infostealer variants including RedLine, Lumma, and Vidar.
First reported: 07.01.2026 11:451 source, 1 articleShow sources
- MFA Failure Enables Infostealer Breach At 50 Enterprises — www.infosecurity-magazine.com — 07.01.2026 11:45
-
Some credentials were harvested from machines infected years before the breach.
First reported: 07.01.2026 11:451 source, 1 articleShow sources
- MFA Failure Enables Infostealer Breach At 50 Enterprises — www.infosecurity-magazine.com — 07.01.2026 11:45
-
Zestix is linked to Russian and Iranian cybercrime groups and operates as an initial access broker (IAB).
First reported: 07.01.2026 11:451 source, 1 articleShow sources
- MFA Failure Enables Infostealer Breach At 50 Enterprises — www.infosecurity-magazine.com — 07.01.2026 11:45
-
Victims include Iberia Airlines, Burris & Macomber, Maida Health, and Intecro Robotics.
First reported: 07.01.2026 11:451 source, 1 articleShow sources
- MFA Failure Enables Infostealer Breach At 50 Enterprises — www.infosecurity-magazine.com — 07.01.2026 11:45