Cybersecurity company Resecurity says hackers obtained login credentials for customer support services used by Amazon, Alibaba, Apple, Goldman, BMW, and others
In an episode that underscores the vulnerability of global computer networks, hackers got ahold of login credentials for data centers …
Context & Ripple Effects
Resecurity has built a niche reporting credential theft at shared infrastructure layers: last year it flagged hackers inside the machines of staff at 21 natural gas suppliers, and this report follows the same pattern — attackers going after the support and data-center access that many large companies share rather than any single victim's network. That makes attribution and remediation awkward, since the affected firms — as in Resecurity's gas-supplier findings — may not even be the original point of entry.
The disclosure also lands in a stretch where credential exposure keeps resurfacing at scale: a researcher recently found an exposed Elastic database with 184M records of login credentials for Apple, Meta, Google, and others, and a supply chain attack once reached 35+ companies including Microsoft and Apple through a shared open source dependency. Customer support portals are a particularly valuable target because they sit at the boundary between a vendor and its enterprise clients.
First-order effects
- The named firms — Amazon, Alibaba, Apple, Goldman, BMW — must now audit whether the stolen support credentials are still valid, rotate them, and review what support staff could access on their behalf, including data-center and account-management functions.
Second-order effects
- Vendors running shared customer support platforms face pressure to tighten authentication (hardware keys, session controls) for support access, since a single credential leak now propagates across their whole client base rather than one account.
Third-order effects
- If credential theft at shared service layers keeps recurring, enterprise buyers will increasingly treat vendor support access as a first-class security boundary in procurement and contracts, demanding audit rights over how support staff reach their environments.
The trend: Attackers are increasingly targeting shared vendor and support infrastructure, where one set of stolen credentials spans dozens of large companies at once.