[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDwECrSQp3SvCb6dKGj23kLZQ1PkxvBKDzCmtafhYGwk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"f92806ee-62d7-4690-8e31-f5f6f726b8da","astrazeneca-breach-exposes-critical-infrastructure-data","a2f820a8-9761-4a6c-a6cb-7e5f944f3772","AstraZeneca Breach Exposes Critical Infrastructure Data","The Lapsus$ group successfully infiltrated AstraZeneca's systems and exfiltrated 3GB of highly sensitive data, including source code, credentials, tokens, and employee information. This breach demonstrates how attackers can gain unauthorized access to critical systems and extract valuable intellectual property and infrastructure details. The theft of credentials and tokens is particularly concerning as these can be used for further attacks or sold to other threat actors. The incident highlights the severe business and security risks when access controls fail to protect sensitive corporate assets.","**Long-term improvements:**\n- This breach could have been prevented through implementation of robust access controls including multi-factor authentication, privileged access management, and zero-trust architecture principles\n- Regular access reviews and credential rotation policies would limit the exposure of tokens and credentials\n\n**Detection measures:**\n- Data loss prevention (DLP) solutions and network segmentation could have detected and blocked the exfiltration of 3GB of sensitive data\n- proper classification and encryption of sensitive data repositories, along with monitoring of unusual access patterns to code repositories and cloud infrastructure, would have provided early warning signs of the breach",[12,13,14,15,16,17,18],"CIS Control 6","CIS Control 13","NIST AC-2","NIST AC-6","NIST SC-7","ISO 27001 A.9.1","GDPR Article 32","published","2026-03-24T15:43:08.433921+00:00","2026-03-24T15:43:08.323+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fwww.securityweek.com\u002Fextortion-group-claims-it-hacked-astrazeneca\u002F","extortion-group-claims-it-hacked-astrazeneca","Extortion Group Claims It Hacked AstraZeneca",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":34,"name":35,"slug":36,"description":37,"color":38},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]