Back to all lessons
Awareness Lessons
6 months ago

Supreme Court breach highlights credential theft and monitoring gaps

Nicholas Moore successfully breached multiple high-profile government systems including the U.S. Supreme Court's filing system using stolen credentials, demonstrating critical failures in access control and detection capabilities. The attacker was able to maintain access long enough to extract and publicly post victims' personal information on social media without detection. This incident highlights how compromised credentials can provide extensive access to sensitive government systems when proper monitoring and access controls are absent.

Tactical Insight

Immediate actions

  • Implement multi-factor authentication (MFA) for all administrative and privileged accounts
  • Deploy real-time monitoring for unusual access patterns and credential usage
  • Conduct immediate audit of all user accounts and disable inactive or suspicious credentials

Long-term improvements

  • Establish privileged access management (PAM) solutions to control and monitor high-risk accounts
  • Implement zero-trust architecture requiring continuous verification of user identity and device status
  • Deploy user and entity behavior analytics (UEBA) to detect anomalous activities

Detection measures

  • Enable alerting for data exfiltration attempts and large file downloads
  • Monitor social media and dark web for leaked organizational data
  • Implement data loss prevention (DLP) tools to prevent unauthorized data sharing