Menu
Browse

Cyber Incident Victim: SANS Institute

Date:

Aug 2020

Location:

United States of America

Summary

A cybersecurity training organization experienced a data breach when an employee fell victim to a phishing attack, compromising their email account. The attacker configured a rule forwarding over 500 emails containing approximately 28,000 records of personal information, including email addresses, full names, phone numbers, job titles, company affiliations, and physical addresses—though no passwords or financial data were exposed. Internal digital forensics instructors led the investigation, confirming no additional systems were compromised while implementing security enhancements. Affected individuals were notified of potential targeted phishing attempts leveraging the stolen data, and the organization planned to share investigative insights with the community post-review.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On August 6, 2020, the SANS Institute, a prominent cybersecurity training organization, discovered a data breach during a routine review of its email configuration systems. The breach originated from a phishing attack targeting a single employee, whose compromised email account allowed threat actors to establish persistent access. Attackers configured a rule within the account to forward all incoming emails—totaling 513 messages—to an external email address under their control. They also installed a malicious add-on within the Office 365 environment to facilitate data exfiltration. The forwarded emails contained approximately 28,000 records of personally identifiable information (PII) belonging to SANS members, including full names, email addresses, phone numbers, physical addresses, job titles, and company affiliations. No passwords, financial data, or credit card information was exposed in the incident. SANS attributed the breach solely to the phishing email’s success in compromising the employee’s account, with no evidence of broader system infiltration beyond the targeted mailbox.

Cyber Incident Image

SANS mobilized its internal cybersecurity instructors, including digital forensics experts, to lead the investigation and containment efforts. The response focused on identifying the attack’s scope, eliminating the malicious email-forwarding rule and add-on, and hardening email security configurations to prevent recurrence. Affected individuals received direct notifications advising vigilance against targeted phishing campaigns leveraging the stolen PII. The organization committed to sharing technical findings from its investigation via a future webcast, intending to translate the incident into actionable insights for the broader security community. No additional compromises or systemic vulnerabilities were identified during the investigation, confirming the breach’s isolation to the initially compromised account and its forwarded email data.

Sources
Sources available to members
1 source