An incident response team investigating a breach at a regional cloud healthcare provider discovers that infrastructure automation scripts were modified to disable TLS verification across internal microservices. Forensic analysis shows the modification was performed using an active API token originally issued to a former system Administrator who recently left the organization on poor terms. Although the connection originated from an anonymized VPN node commonly associated with political hacktivist campaigns, no external software vulnerabilities or social engineering attacks were involved. Which threat actor type and attack vector combination primary characterizes this incident?
- Insider threat utilizing a direct credential access vectorAnswer
- BHacktivist collective utilizing a social engineering vector
- CNation-state threat actor utilizing an upstream supply chain vector
- DShadow IT operator utilizing an unpatched perimeter vulnerability vector
Answer
An insider threat utilizing a direct credential access vector best characterizes the incident.
An insider threat includes current or former employees who retain authentic credentials or possess inside knowledge of infrastructure operations. Because the attack utilized legitimate API keys previously assigned to an offboarded administrator, the primary threat actor classification is an insider threat, and the attack vector is direct credential abuse.
Step-by-Step Solution
Key Concept
Threat Actor Classification and Attack Vector Identification
Estimated Time:2m 30s