[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fP33mDjTMkG5HHdhiuhppn5jAMbY-PHNXtcaO3jhN_uc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"595d44d5-753b-442f-9489-c2f782a39c33","government-email-credentials-compromised-in-credential-theft-operation","e7c24d2c-7a4d-4b9e-a560-86f1d04ef788","Government Email Credentials Compromised in Credential Theft Operation","A threat actor is selling stolen email credentials from critical Israeli government agencies and international organizations, including law enforcement, justice, and education sectors. The breach likely resulted from weak password practices, credential reuse, or successful phishing campaigns targeting government employees. These compromised credentials provide attackers with legitimate access to sensitive government communications and serve as a launching point for further attacks through spear phishing and lateral movement. The incident demonstrates how credential theft can bypass traditional security perimeters and create cascading security risks across interconnected government systems.","**Immediate actions:**\n- Force password resets for all potentially compromised accounts and implement temporary additional authentication requirements\n- Conduct emergency security awareness training focused on phishing recognition and credential protection\n- Review and audit all recent account access patterns for signs of unauthorized use\n\n**Long-term improvements:**\n- Deploy multi-factor authentication across all government email systems and critical applications\n- Implement privileged access management solutions with regular credential rotation for administrative accounts\n- Establish mandatory cybersecurity training programs with regular phishing simulation exercises\n\n**Detection measures:**\n- Deploy advanced email security solutions with behavioral analysis to detect credential-based attacks\n- Implement continuous monitoring for unusual login patterns, geographic anomalies, and privilege escalation attempts",[12,13,14,15,16,17,18,19],"CIS Control 6","CIS Control 14","NIST AC-2","NIST AC-3","NIST IA-2","NIST AT-2","ISO 27001 A.9.2.1","ISO 27001 A.18.1.4","published","2026-03-31T16:09:11.949336+00:00","2026-03-31T16:09:11.86+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fdarkwebinformer.com\u002Fthreat-actor-selling-email-credentials-for-israeli-government-agencies-organizations-and-international-targets-including-israel-police-ministry-of-justice-and-quebec-education-board\u002F","threat-actor-selling-email-credentials-for-israeli-government-agencies-organizat","Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":35,"name":36,"slug":37,"description":38,"color":39},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]