[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fuPbWqUECP5xbqRI9jLLPkaBHQn_nzrC5ak2qLUvVfrk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"8c85dff3-1d01-4179-9a87-de2b59f1da78","executive-email-compromise-leads-to-5-month-data-exfiltration","8c68cd23-e0c3-45e6-ba7d-976b3da5060a","Executive Email Compromise Leads to 5-Month Data Exfiltration","Attackers compromised a senior executive's email account at a global stock exchange and maintained undetected access for 150 days, exfiltrating sensitive market data through legitimate cloud services like Dropbox and OneDrive. The prolonged breach demonstrates critical failures in privileged account monitoring and insider threat detection capabilities. By using legitimate file-sharing services, the attackers successfully evaded traditional security controls that focus on blocking malicious domains rather than monitoring data exfiltration patterns. This incident highlights how high-value targets like financial executives require enhanced security controls due to their access to market-sensitive information.","**Immediate actions:**\n- Implement multi-factor authentication for all executive and privileged user accounts\n- Deploy data loss prevention (DLP) solutions to monitor file uploads to cloud storage services\n- Enable enhanced logging and monitoring for all privileged user activities\n\n**Long-term improvements:**\n- Establish privileged access management (PAM) with time-limited access and approval workflows\n- Implement user behavior analytics to detect anomalous data access patterns\n- Create network segmentation to isolate executive systems from general corporate networks\n\n**Detection measures:**\n- Configure alerts for unusual file sharing activities to external cloud services\n- Monitor email forwarding rules and unusual login patterns for executive accounts\n- Implement regular access reviews and recertification for privileged accounts",[12,13,14,15,16,17,18,19],"CIS Control 5","CIS Control 6","CIS Control 8","NIST AC-2","NIST AC-6","NIST AU-2","NIST SI-4","GDPR Article 32","published","2026-06-03T14:07:24.158668+00:00","2026-06-03T14:07:24.067+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.securityweek.com\u002Fhackers-target-global-stock-exchange-in-espionage-operation\u002F","hackers-target-global-stock-exchange-in-espionage-operation-c73de5","Hackers Target Global Stock Exchange in Espionage Operation",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]