One legacy VPN account without MFA took down critical infrastructure for six days.
Colonial is why "MFA everywhere" stopped being optional for anything touching a network perimeter.
In May 2021, a ransomware gang shut down the largest fuel pipeline on the US East Coast.
Gas stations ran dry. Airlines worried about jet fuel. The CEO paid a $4.4 million Bitcoin ransom. 🧵
Colonial shut down the pipeline proactively — not because hackers had reached it, but because they couldn't verify they hadn't.
The FBI eventually recovered $2.3 million of the ransom. DarkSide disbanded publicly, then reformed under new branding months later.
Capital One paid $80 million in regulatory fines. The technical root cause was a misconfigured WAF — a single missed setting on a critical control.
Sometimes the threat is an insider who knows exactly where to look.
In 2019, a former AWS engineer scraped 100 million Capital One customer records from a misconfigured cloud bucket.
She didn't sell the data. She posted about it on Slack and GitHub. Her handle was "erratic." 🧵
She was caught because she talked about the breach in a private Slack channel — and another user reported her. The FBI arrested her within weeks.
Multiple people who knew her said the warning signs were there long before the breach.
BEC remains one of the highest-dollar cybercrime categories because it bypasses most technical controls.
If your wire transfer process trusts email alone, you're one typo away from this story.
In 2016, the board of an Austrian aerospace company fired its CEO.
Not for poor earnings. For approving €50 million in wire transfers to fraudsters who impersonated another executive in email. 🧵
The board held the CEO personally responsible and terminated him immediately. Stock dropped. Auditors got involved.
The company recovered roughly €10 million through legal action. The rest was gone.
Ashley Madison is the textbook case for why "we'll delete your data" needs to be verifiable, not marketing copy.
Promising something you don't do is a liability waiting for a breach to expose it.
Ashley Madison promised users a paid "full delete" — their data wiped permanently for $19.
When hackers breached the site in 2015, they found those records were never deleted.
37 million accounts. Names, addresses, credit cards. 🧵
The CEO resigned within a week. The company settled with the FTC for $1.6 million. Multiple suicides were linked to the exposure.
The breach wasn't sophisticated. It was SQL injection — one of the oldest vulnerability classes in the book.
The cover-up became a bigger liability than the breach itself.
Sullivan had spent his career investigating criminals. He ended up facing prison time for how he handled one.
In 2016, hackers stole 57 million Uber rider and driver records.
Instead of reporting it, Uber paid them $100,000 to delete the data and stay quiet.
The CISO was eventually convicted for covering it up. 🧵
Uber kept the breach secret for over a year. When it surfaced, Sullivan was fired.
In 2022, a jury found him guilty of obstructing justice — the first time a sitting CISO was convicted for handling a breach this way.