“John, did you hear about the Acme CRM breach?”
John, a Cyber Threat Intelligence (CTI) analyst, turns to look at his CISO. He seems a bit rattled.
John responds, “Yeah. Huge story.”
“Massive. The board is worried and wants to know if this puts us at risk. We’re secure, right?”
John hesitates.“Let me get back to you on that.”
The CISO walks away. John races to his desk.
Step 1: Breach hunting
For a CTI analyst, hearing about a large breach often means the earliest warning signs have already passed, making fast validation critical.
Luckily for John, he has access to Bitsight Threat Intelligence’s Adversary Intelligence module, part of our larger Cyber Threat Intelligence solution, where he can investigate known campaigns and relevant IOCs to gain adversary context fast and better identify and prioritize threats.
John opens the module and searches “Acme CRM.”
Instead of a single entry, he lands on a campaign tracked under a different name, ShinyHunters, with the Acme CRM breach listed as an alias. Oftentimes, a breach has alias names because the media refers to the same incident with different names depending on context and perspective. Connecting the alias names centralizes the data.
He starts analyzing the information.
The campaign description outlines how the breaches unfolded and the techniques the adversaries used to succeed, giving John early insight into where his defenses may need to be strengthened.
15 confirmed victims.
This isn’t an isolated breach. It’s a scalable campaign with operational momentum and likely additional, unconfirmed victims.
Adversary groups involved:
- Scattered Spider
- Lapsus
- ShinyHunters
Seeing multiple adversary groups tied to the same campaign signals that this isn’t a clean, single-actor intrusion but a multi-phase operation involving shared access, infrastructure, or handoffs between groups. This broadens the threat model: more entry points, more techniques, and more infrastructure to account for.
Step 2: Establish relevance
John scrolls down to view the timeline of the campaign, affected sectors, and locations.
Timeline:
- Multiple distinct attack events in the span of a month.
This indicates sustained activity and not a single burst.
Campaign activity data:
- Sector: Finance
- Geography: France
John’s company operates in the financial sector and is headquartered in France.
While this doesn’t confirm targeting, the combination of sustained activity, sector overlap, and geographic alignment is enough to treat the campaign as operationally relevant.