From a job posting to Domain Admin in six days
- Objective
- Access the core payment-processing database of a regional bank
- Path
- A developer’s home-network NAS, exposed by a forgotten port forward, yielded corporate VPN credentials saved in a browser profile. MFA was enforced — but the VPN portal allowed push-fatigue spam. Push #14 was approved on a Friday evening. From the VPN, an outdated internal CI server reused the same local-admin password across 60+ hosts; the DPAPI-protected credentials of a tier-0 operator were recoverable from a misconfigured build agent.
- Detected
- The MFA-fatigue burst triggered no alert; the pass-the-hash across CI hosts fired a single low-severity rule nobody owned
After: number-matching + PIN enforced, local-admin passwords randomized, unowned alert rules reassigned — the same scenario retested clean three months later.