[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f57gQx4jm-szAyHGrT6_HT-bMrvbby2KHNJBTFK8duXI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"3a31cd2c-2ee4-407f-9b8f-5dd9c33f44c4","nation-state-actors-exploit-stolen-credentials-to-access-600k-government-records","a9e0fa75-0c74-42a0-ab0f-39d366d4f635","Nation-State Actors Exploit Stolen Credentials to Access 600K+ Government Records","Lithuanian authorities suffered a massive breach when attackers used stolen credentials from authorized institutions to access over 600,000 national register entries. The incident highlights how compromised institutional access can bypass traditional perimeter defenses, especially when targeting high-value government databases. The suspected foreign state involvement demonstrates how nation-state actors specifically target government systems containing sensitive citizen and property data. This breach underscores the critical need for robust credential management and privileged access controls in government systems handling national infrastructure data.","**Immediate actions:**\n- Implement multi-factor authentication for all privileged accounts accessing national databases\n- Conduct emergency audit of all institutional access credentials and revoke suspicious accounts\n- Deploy real-time monitoring for unusual access patterns to sensitive government registers\n\n**Long-term improvements:**\n- Establish zero-trust architecture requiring continuous verification for database access\n- Implement role-based access controls with principle of least privilege for institutional users\n- Create segregated access tiers with additional authentication for highly sensitive national data\n\n**Detection measures:**\n- Deploy behavioral analytics to identify anomalous access patterns from authorized institutions\n- Establish automated alerts for bulk data access or downloads from national registers\n- Implement cross-reference monitoring to detect credential use across multiple systems",[12,13,14,15,16,17],"CIS Control 6","NIST AC-2","NIST AC-3","NIST AC-6","ISO 27001 A.9.1","GDPR Article 32","published","2026-05-27T04:54:56.878497+00:00","2026-05-27T04:54:56.793+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Flithuania-suspects-foreign-involvement-in-data-leak-of-over-600000-national-register-entries\u002F","lithuania-suspects-foreign-involvement-in-data-leak-of-over-600-000-national-reg-5005e4","Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]