Category: News

  • Hackers Exploit Microsoft Entra ID to Access Sensitive Corporate Data

    Hackers Exploit Microsoft Entra ID to Access Sensitive Corporate Data

    Cybercriminals are increasingly targeting cloud identity platforms, and recent reports reveal a concerning trend: attackers are abusing compromised Microsoft Entra ID accounts to gain unauthorized access to sensitive data stored across Microsoft 365 and Microsoft Azure environments.

    Security researchers recently uncovered campaigns where threat actors leveraged tools such as TeamFiltration to target tens of thousands of Entra ID accounts globally. The attacks focused on account takeover, data exfiltration, and persistent access to enterprise cloud environments.

    For organizations relying heavily on Microsoft’s cloud ecosystem, this serves as another reminder that identity is now the primary security perimeter.

    Understanding the Attack

    According to cybersecurity reports, attackers used compromised credentials, API abuse, and legitimate Microsoft services to bypass traditional security controls. In many cases, threat actors did not rely on malware; instead, they abused trusted authentication mechanisms already present within organizations.

    The attack chain generally follows this pattern:

    1. Credential theft through phishing or social engineering
    2. Unauthorized login into Entra ID accounts
    3. Enumeration of Microsoft 365 and Azure resources
    4. Privilege escalation or persistence mechanisms
    5. Data exfiltration from cloud storage, email, and collaboration platforms

    Researchers noted that attackers leveraged legitimate APIs and cloud administration features, making detection significantly harder because activities often appeared as normal user behavior.

    Why Microsoft Entra ID Is a High-Value Target

    Microsoft Entra ID acts as the central authentication and identity management layer for many enterprises. Once attackers gain access to an Entra ID account, they may inherit access to:

    • Corporate emails
    • SharePoint and OneDrive data
    • Microsoft Teams conversations
    • Azure virtual machines and storage
    • Administrative dashboards
    • Third-party SaaS integrations

    Because Entra ID enables single sign-on (SSO), one compromised account can unlock multiple business-critical systems simultaneously.

    Key Risks to Organizations

    1. Silent Data Exfiltration

    Attackers can quietly export sensitive business information without deploying ransomware or triggering endpoint alerts.

    2. Persistence in Cloud Environments

    Threat actors may create additional identities, OAuth applications, or tokens to maintain long-term access.

    3. Abuse of Trusted Tools

    Using legitimate Microsoft APIs and administrative functions helps attackers evade conventional security monitoring.

    4. Business Disruption and Compliance Exposure

    Stolen customer data, intellectual property, or financial records can lead to operational downtime, reputational damage, and regulatory penalties.

    Indicators of Compromise

    Organizations should watch for:

    • Unusual login locations or impossible travel events
    • Suspicious OAuth application consent grants
    • Excessive Microsoft Graph API activity
    • Unexpected mailbox exports or SharePoint downloads
    • Privilege escalation attempts
    • Dormant accounts suddenly becoming active

    Continuous monitoring of identity activity is now essential for modern cybersecurity operations.

    How Organizations Can Protect Themselves

    Enable Multi-Factor Authentication Everywhere

    Strong MFA significantly reduces the effectiveness of credential theft attacks.

    Implement Conditional Access Policies

    Restrict access based on device trust, geography, user risk, and session behavior.

    Adopt Least Privilege Access

    Limit administrative privileges and regularly review access permissions.

    Monitor Identity and API Activity

    Deploy advanced identity threat detection and cloud security monitoring solutions.

    Review OAuth and Third-Party Integrations

    Attackers increasingly exploit excessive permissions granted to cloud applications.

    Conduct Regular Security Awareness Training

    Social engineering and phishing remain the most common entry points for attackers.

    The Bigger Cybersecurity Lesson

    Modern cyberattacks are shifting away from traditional malware toward identity-centric compromise. Attackers understand that cloud identities provide direct access to business operations, making them more valuable than endpoints alone.

    The abuse of Microsoft Entra ID accounts demonstrates how threat actors are evolving to exploit trust relationships within cloud ecosystems rather than relying solely on software vulnerabilities.

    Organizations must therefore move beyond perimeter-based security and adopt an identity-first security strategy that prioritizes:

    • Continuous authentication
    • Real-time monitoring
    • Zero Trust architecture
    • Cloud-native threat detection
    • Proactive incident response

    Final Thoughts

    The recent Entra ID abuse campaigns reinforce a critical reality: identity security is business security. As enterprises continue migrating workloads to the cloud, protecting identity platforms becomes essential to safeguarding data, operations, and customer trust.

    At Summit Systems ISSP, we encourage organizations to continuously assess their cloud security posture, strengthen identity protection mechanisms, and invest in proactive cybersecurity strategies that can detect and respond to modern threats before significant damage occurs.

    Cybercriminals are evolving rapidly — and organizations must evolve even faster.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information.

  • What the Canvas Cyber Incident Means for Universities and Why Cyber Resilience Matters

    What the Canvas Cyber Incident Means for Universities and Why Cyber Resilience Matters

    The recent cyber incident involving the widely used Canvas Learning Management System (LMS) has become a wake-up call for universities and educational institutions around the world. Over the weekend, reports emerged that hackers targeted the platform used by thousands of schools and universities globally, disrupting online learning activities during one of the most critical periods of the academic calendar.

    For institutions that depend heavily on digital learning environments, the incident highlights an uncomfortable reality: education has become a prime target for cybercriminals.

    What Happened?

    Canvas, developed by Instructure, is one of the world’s most widely adopted learning management systems. The platform enables universities to manage coursework, assignments, exams, student communications, and online collaboration.

    According to public reports, threat actors allegedly gained unauthorized access to portions of the platform and disrupted services for multiple institutions. Some universities temporarily restricted access while investigations were underway.

    Early reports suggest that exposed information may include:

    • Student names
    • Email addresses
    • Student identification numbers
    • Internal messages and academic communications

    At the time of reporting, there has been no confirmed evidence that financial information or passwords were compromised. However, the event caused significant operational disruption during examination and coursework submission periods.

    Why Educational Institutions Are Increasingly Targeted

    Universities are particularly attractive to cybercriminals for several reasons:

    1. Large Volumes of Sensitive Data

    Educational institutions store:

    • Student records
    • Research data
    • Financial information
    • Staff credentials
    • Intellectual property

    This makes universities valuable targets for ransomware groups and data theft operations.

    2. Complex IT Environments

    Many institutions operate:

    • Legacy systems
    • Hybrid cloud environments
    • Third-party learning platforms
    • Open networks for students and faculty

    These interconnected systems can create security gaps if not continuously monitored and maintained.

    3. High Dependence on Availability

    When learning platforms go offline, academic operations can halt immediately. Cybercriminals understand the pressure institutions face during exams, admissions periods, and registration cycles.

    The Bigger Lesson: Cybersecurity Is Now Operational Risk Management

    The Canvas incident demonstrates that cybersecurity is no longer just an IT issue — it is an operational continuity issue.

    Organizations must prepare for:

    • Third-party vendor compromises
    • Supply chain attacks
    • Credential theft
    • Ransomware attempts
    • Data exfiltration incidents

    Even when an institution’s internal systems remain secure, vulnerabilities in external service providers can still create major disruption.

    Key Cybersecurity Measures Institutions Should Prioritize

    To strengthen resilience against similar incidents, organizations should consider:

    Vendor Risk Assessments

    Evaluate the cybersecurity posture of all third-party platforms and software providers.

    Multi-Factor Authentication (MFA)

    Reduce the risk of credential-based attacks by enforcing MFA across critical systems.

    Continuous Monitoring

    Implement real-time threat monitoring and incident detection capabilities.

    Incident Response Planning

    Develop and regularly test response plans for cyber incidents and service outages.

    Data Backups and Recovery

    Ensure secure backups are maintained and recovery procedures are validated.

    Security Awareness Training

    Educate staff and users on phishing, credential security, and suspicious activity reporting.

    Final Thoughts

    The Canvas cyber incident is another reminder that digital transformation must be matched with strong cybersecurity governance. As educational institutions continue to expand online learning and cloud-based collaboration, proactive cyber resilience becomes essential.

    At Summit Systems ISSP, we believe organizations must move beyond reactive security measures and adopt a comprehensive approach that combines prevention, detection, response, and recovery.

    Cyber threats are evolving rapidly — and resilience is now a critical business requirement, not an optional investment.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • Nike Investigates Alleged Cybersecurity Breach Following Data Leak Threats

    Nike Investigates Alleged Cybersecurity Breach Following Data Leak Threats

    Nike, one of the world’s most recognisable athletic brands, is currently investigating a potential cybersecurity incident after a notorious hacking group publicly claimed to have accessed its systems and threatened to release stolen data unless their demands are met.

    What Happened?

    On January 22, 2026, the WorldLeaks cybercrime gang added Nike to its darknet leak site — a platform frequently used by threat actors to list alleged victims and apply public pressure for ransom payments. The group has positioned a countdown timer, indicating that the purportedly stolen data will be published by January 24 unless negotiations occur. At the time of publishing, neither the volume nor the exact nature of the data allegedly compromised has been fully confirmed.

    Nike has issued a brief statement emphasizing its commitment to consumer privacy and data security, saying it is actively investigating the potential incident and assessing the situation.

    Who Are the Attackers?

    WorldLeaks emerged in 2025 following the dissolution of a previous ransomware syndicate known as Hunters International. Unlike traditional ransomware groups that encrypt systems and demand payment to restore access, WorldLeaks and similar outfits focus primarily on data theft and extortion — threatening to leak sensitive information unless their financial demands are met.

    Security analysts have tied WorldLeaks’ activity to broader trends in extortion-driven cybercrime, where data exfiltration and public disclosure threats have become increasingly common tactics.

    What Is at Stake?

    Details on what exactly was taken remain scarce. Cybersecurity reports suggest the leak could include internal documents, credential lists, and possibly customer or partner data — though these claims are unverified as of now. One independent report mentioned that thousands of internal records may be involved, but official confirmation from Nike remains pending.

    Threat actors like WorldLeaks often employ phishing, exploitation of exposed services, or stolen credentials to gain initial access to corporate networks, though specifics of this incident haven’t been disclosed.

    Broader Context: A Growing Trend

    This event comes amidst a spate of cybersecurity incidents affecting major brands and organisations across industries — from retail to technology and healthcare. In several recent cases, groups have either leaked or threatened to leak sensitive information after claiming access to corporate databases.

    For organisations like Nike, the implications extend beyond immediate operational risk. Public exposure of compromised data can erode customer trust, trigger regulatory scrutiny, and lead to costly remediation if personal information is involved.

    How Companies Can Respond

    In situations like this, best practices for organisations under threat include:

    • Immediate incident response activation, including forensic analysis of affected systems.
    • Transparent communication with stakeholders and affected parties without releasing sensitive internal details.
    • Engagement with experienced cybersecurity partners to guide containment and recovery.
    • Monitoring dark web channels for further threat actor activity related to the incident.

    Proactive measures such as multi-factor authentication (MFA), robust network segmentation, and regular employee security training can also reduce the likelihood of successful intrusions.

    Conclusion

    Nike’s ongoing investigation highlights the evolving tactics of cybercriminals and the tangible risks modern enterprises face in an increasingly digital business environment. While the full impact of the alleged breach remains unclear, the situation underscores the importance of robust cybersecurity posture, rapid incident response, and vigilant monitoring of emerging threats.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • Two US rusted Cybersecurity Professionals Plead Guilty in Major Ransomware Extortion Case

    Two US rusted Cybersecurity Professionals Plead Guilty in Major Ransomware Extortion Case

    Two U.S.-based cybersecurity professionals have pleaded guilty in federal court for their roles in spearheading ransomware attacks that extorted multiple victims across the United States, according to the U.S. Department of Justice.

    The defendants, Ryan Clifford Goldberg of Georgia and Kevin Tyler Martin of Texas, both formerly employed in respected cybersecurity roles, admitted to conspiring to obstruct, delay, or affect commerce through extortion by deploying the notorious ALPHV/BlackCat ransomware in 2023.

    Background & Scope of the Case

    Goldberg and Martin — who previously worked as an incident response manager and a ransomware negotiator, respectively — used their professional expertise and trusted access to identify, infiltrate, and compromise corporate networks.

    The pair operated as affiliates of the BlackCat ransomware group, paying a portion of ransom proceeds to the malware’s administrators in exchange for access to the ransomware platform.

    According to court records, the defendants and a third unnamed co-conspirator targeted numerous U.S. companies, including victims in healthcare, engineering, and technology sectors. In one instance, a Florida medical company paid over $1.2 million in Bitcoin to regain access to encrypted files — funds that were subsequently laundered.

    Consequences & Legal Outcomes

    Goldberg and Martin have entered guilty pleas to federal charges of conspiracy to commit extortion. They face up to 20 years in prison, and sentencing has been scheduled for March 12, 2026.

    In addition to potential incarceration, both defendants are expected to forfeit proceeds derived from the illicit scheme as part of their plea agreements.

    Industry Impact & Lessons Learned

    This case marks a sobering reminder that insider threats — even from experienced cybersecurity professionals — pose real and evolving risks to organizations. It underscores several key imperatives for businesses and security teams:

    • Vetting & Oversight: Robust background screening and continuous monitoring of personnel with privileged system access is essential.
    • Ethics & Accountability: Strong ethical codes and enforceable professional standards in cybersecurity can deter misuse of skills for illicit ends.
    • Third-Party Risk Management: Organizations must evaluate not only their internal teams but also the trustworthiness of external partners, especially those engaged in incident response and threat mitigation services.

    Closing Thought

    While ransomware remains a pervasive global threat, cases like this highlight the deep importance of integrity in the cybersecurity profession. Upholding trustworthiness and ethical conduct isn’t just best practice — it’s foundational to protecting businesses, clients, and digital infrastructure.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • The Billion-Naira Bank Fraud Case: A Deep Dive Into Insider Threats and How Summit Systems ISSP Can Help Organizations Stay Protected

    The Billion-Naira Bank Fraud Case: A Deep Dive Into Insider Threats and How Summit Systems ISSP Can Help Organizations Stay Protected

    The Billion-Naira Bank Fraud Case: A Deep Dive Into Insider Threats and How Summit Systems ISSP Can Help Organizations Stay Protected

    Nigeria recently witnessed one of the largest financial fraud scandals in its banking history — a case where a former manager of a major bank allegedly diverted billions of naira through sophisticated internal manipulation.

    This incident has raised serious questions about insider threats, weak internal controls, and the need for robust cybersecurity frameworks across financial institutions.

    At Summit Systems ISSP, we believe this case offers powerful lessons for every organization that handles financial transactions, sensitive data, or privileged access.

    How the Fraud Was Carried Out

    Investigators revealed that the former bank manager held a strategic role in the bank’s electronic settlement and transaction-processing operations. This position gave him privileged access to process financial reversals — the kind of internal operations that typically require tight oversight.

    Instead of crediting customers who requested reversals, he allegedly:

    • Redirected large sums into a merchant account under his control.
    • Distributed the funds into about 98 first-beneficiary accounts, including accounts linked to associates.
    • Further funneled the money into over 1,000 secondary accounts, creating a complex laundering trail.
    • Converted part of the funds into foreign currency and cryptocurrency, making tracking even more difficult.

    The scheme reportedly continued for years until a customer complaint triggered an internal review, ultimately uncovering the suspicious patterns.

    Legal Actions and Asset Forfeiture

    Following the bank’s report to law enforcement, the case escalated quickly:

    • Multiple accounts were frozen following court orders.
    • Investigators traced billions to personal and affiliate accounts.
    • Some of the recovered funds — running into billions of naira and hundreds of thousands of dollars — were ordered forfeited to the Federal Government after court proceedings.
    • Authorities also discovered that a portion of the diverted funds had already been moved through crypto channels or withdrawn entirely.

    While significant amounts were recovered, the overall loss remains unprecedented.

    What This Scandal Reveals: The True Risk of Insider Threats

    This case is a stark reminder that the most damaging cybersecurity risks often come from inside the organization.

    Major internal control weaknesses exposed:

    • Excessive privilege given to one individual
    • Lack of Segregation of Duties (SoD) for sensitive processes
    • No automated alerts to detect abnormal financial reversals
    • Weak monitoring of privileged accounts
    • Delayed auditing, allowing the fraudulent activity to grow unnoticed
    • Insufficient oversight over digital settlements and merchant accounts

    External attackers are dangerous — but an insider with unrestricted access can cause catastrophic damage.

    How Summit Systems ISSP Helps Organizations Prevent Incidents Like This

    At Summit Systems ISSP, our mission is to help organizations strengthen their security posture and eliminate vulnerabilities that enable crimes like this one.

    Below are key ways we support organizations across Nigeria and beyond:

    1. Comprehensive Cybersecurity Risk & Gap Assessment: We evaluate your systems, access controls, workflows, and digital operations to identify loopholes that insider threats can exploit.

    This includes:

    • Privilege and access review
    • Transaction monitoring gaps
    • Process weaknesses
    • Audit deficiencies
    • Policy compliance levels

    2. Implementation of NIST CSF 2.0 Framework: We guide organizations in adopting the globally recognized NIST Cybersecurity Framework to strengthen:

    • Identification of risks
    • Protection measures
    • Detection capabilities
    • Response plans
    • Recovery mechanisms

    This ensures your systems follow industry best practices.

    3. Insider-Threat Monitoring & Fraud Detection Systems: We design programs that monitor:

    • Unusual transactions
    • Suspicious account behavior
    • Unauthorized access attempts
    • Privilege escalations
    • Data transfers and policy violations

    These tools help detect threats long before they escalate into billion-naira losses.

    4. Deployment of Real-Time Monitoring & Alerting Tools: Automated tools give organizations immediate visibility into:

    • High-risk transactions
    • System changes
    • Suspicious login activity
    • Settlement and reversal anomalies

    This ensures threats are detected in minutes — not years.

    5. Cybersecurity Policy Development & Governance: Summit Systems ISSP helps organizations build strong internal structures through:

    • Privileged Access Management (PAM)
    • Segregation of Duties (SoD)
    • Multi-level authorization workflows
    • Continuous access reviews
    • Staff accountability frameworks

    6. Specialized Staff Training & Awareness Programs: We equip employees with the knowledge to recognize internal fraud signals, understand ethical access control, and maintain a secure cyber culture.

    7. Incident Response & Investigative Support: If an incident occurs, our team assists with:

    • Containing the breach
    • Tracing transactions
    • Digital forensics
    • Evidence preservation
    • Reporting and regulatory compliance

    The Big Lesson: Prevention Is Always Cheaper Than Recovery

    This billion-naira fraud case shows that even the biggest and most reputable institutions can suffer massive damage due to insider abuse and weak internal controls.

    But with the right cybersecurity strategy, automation, and governance framework, your organization can drastically reduce the likelihood of such incidents.

    At Summit Systems ISSP, we help businesses build resilience — not just security.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this information

  • The New Frontier of Cyber Threats: AI-Powered Malware Mutates and Collects Data During Execution, Google Warns – A Summit Systems ISSP Perspective

    The New Frontier of Cyber Threats: AI-Powered Malware Mutates and Collects Data During Execution, Google Warns – A Summit Systems ISSP Perspective

    The cybersecurity world is bracing for a new and formidable challenge: malware that leverages Artificial Intelligence (AI) during its execution to mutate and collect data. Google’s recent warnings highlight a significant shift in the threat landscape, signaling a future where traditional defenses may no longer be sufficient. At Summit Systems ISSP, we are closely monitoring these developments and are here to help our clients understand and prepare for this evolved form of cyber warfare.

    For years, malware has grown in sophistication, but the integration of AI takes it to an unprecedented level. Previously, malware operated on predefined scripts and behaviors. Now, with AI capabilities, malicious software can learn, adapt, and make autonomous decisions in real-time within a compromised system.

    What Does AI-Powered Malware Mean for Your Organization?

    This new breed of threat introduces several critical concerns:

    1. Dynamic Mutation and Evasion: Traditional antivirus and endpoint detection and response (EDR) solutions often rely on signature-based detection or identifying known behavioral patterns. AI-powered malware can dynamically mutate its code, obfuscate its presence, and alter its attack vectors during execution. This makes it far more difficult for static security tools to identify and quarantine, allowing it to bypass defenses that rely on recognizing fixed characteristics.
    2. Intelligent Data Collection: Beyond simply exfiltrating data, AI allows malware to “intelligently” identify and prioritize valuable information. It can analyze the compromised environment, understand the hierarchy of files and systems, and determine which data sets are most critical or sensitive to the victim organization. This ensures that threat actors gain access to the most impactful information, maximizing the damage or ransom potential.
    3. Adaptive Persistence and Lateral Movement: An AI-driven threat can learn the network topology, identify unmonitored pathways, and adapt its methods to maintain persistence even after initial detection attempts. It can autonomously explore the network, identify new targets, and propagate more effectively, making eradication a far more complex task.
    4. Enhanced Social Engineering: While not directly “during execution,” the underlying AI capabilities could also extend to generating highly personalized phishing attacks based on collected intelligence, making initial compromise more likely.

    Summit Systems ISSP’s Response to the AI Threat

    At Summit Systems ISSP, we recognize that the rise of AI-powered malware demands an evolution in our defense strategies. Our approach focuses on several key areas to combat these advanced threats:

    • Next-Generation Endpoint Protection: We emphasize solutions that incorporate advanced behavioral analytics, machine learning, and AI to detect anomalous activities that indicate the presence of sophisticated, mutating malware, rather than relying solely on signatures.
    • Proactive Threat Hunting: Our security operations center (SOC) analysts actively hunt for subtle indicators of compromise (IOCs) and TTPs that AI-powered malware might leave behind, going beyond automated alerts.
    • Deception Technologies: Deploying honeypots and deception networks can lure AI-powered malware into controlled environments, allowing us to observe its behavior and gather intelligence without risking production systems.
    • Robust Network Segmentation: Limiting lateral movement through strict network segmentation is more crucial than ever. If AI malware breaches one segment, it will be significantly harder for it to spread to critical systems.
    • Employee Training & Awareness: While AI malware is sophisticated, the human element often remains the weakest link. Continuous training on identifying phishing attempts and practicing good cyber hygiene is still paramount.
    • Continuous Threat Intelligence: We integrate the latest threat intelligence, including warnings from industry leaders like Google, into our platforms and advisories to ensure our defenses are always up-to-date against emerging AI-driven tactics.

    Staying Ahead in the AI Arms Race

    The development of AI-powered malware marks a new phase in cybersecurity. It underscores the urgent need for organizations to move beyond foundational security and invest in advanced, adaptive defenses. At Summit Systems ISSP, we are committed to providing the expertise, technologies, and strategic guidance required to protect your organization against these evolving and intelligent threats.

    Don’t wait for your systems to become a learning ground for malicious AI. Contact Summit Systems ISSP today to assess your current defenses and fortify your security posture against the threats of tomorrow.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Summitsystemsissp assumes no liability for the accuracy or consequences of using this