/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Industrial cybersecurity firm Dragos says a known cybercrime group gained access to its SharePoint cloud service on May 8 but didn't breach its internal network

Industrial cybersecurity company Dragos today disclosed what it describes as a “cybersecurity event” after a known cybercrime gang attempted …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The incident highlights the boundary between a cloud collaboration environment and an industrial cyber defender’s core network: Dragos says the access did not cross that boundary. SharePoint has also appeared in prior intrusion reporting, including municipal-network breaches tied to a SharePoint vulnerability, making access controls around the service consequential even when a broader compromise is avoided.

First-order effects

  • Dragos must investigate the SharePoint access, assess exposed material, and contain the affected cloud-service account or tenant while its internal network remains outside the reported breach.
  • Customers and partners gain a concrete disclosure of the incident’s stated scope: cloud-service access by a known criminal group, rather than confirmed access to Dragos’s internal systems.

Second-order effects

  • Security teams using SharePoint, particularly those handling operational or sensitive customer information, may reassess identity controls, permissions, logging, and separation between collaboration tools and core networks.
  • The event reinforces demand for cyber-defense architectures that can limit an attacker’s movement after a cloud-service foothold, rather than treating SaaS access as equivalent to network access.

Third-order effects

  • If cloud collaboration platforms remain recurring entry points, segmentation and identity governance will become more central measures of resilience for industrial and critical-infrastructure security providers.
  • The distinction between a SaaS incident and an internal-network breach may increasingly shape disclosure practices, as organizations are pressed to state both the initial access point and the limits of attacker movement.

The trend: This is one data point in the shift toward ecosystem cyber defense, where protecting connected cloud services and containing their blast radius matter as much as perimeter security.

Discussion

  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    “On May 8, 2023, a known cybercriminal group attempted and failed at an extortion scheme against Dragos.  No Dragos systems were breached, including anything related to the Dragos Platform. ”  —  https://www.dragos.com/...
  • @dragosinc @dragosinc on x
    It's time to destigmatize security events. Yes it happens at security companies and here's why we need to talk about it. #cybersecurity #icscybersecurity #otcybersecurity #industrialcybersecurity #criticalinfrastructureprotection https://hubs.la/...
  • @arekfurt @arekfurt on x
    Looks like Dragos handled dealing with these scumbags (note the threats against family members) here quite well overall. Attacks targeted at new hires are definitely increasing, with crooks monitoring linkedIn for new users they can compromise more easily. https://www.dragos.com/…
  • @bushidotoken Will on x
    I gave a brief comment to @BleepinComputer on the IOCs disclosed in the incident by Dragos, the 144.202.42[.]216 IP is widely reported to be used by ransomware groups and has likely changed hands a few times 🔍 https://www.bleepingcomputer.com/ ...
  • @snlyngaas Sean Lyngaas on x
    Industrial security firm Dragos says it blocked a cybercriminal group that appeared intent on deploying ransomware after the group hacked the personal email of a new Dragos employee & posed as the employee to access a contract management system. https://www.dragos.com/...
  • @vxunderground @vxunderground on x
    Update: This appears to be related to this incident Dragos disclosed earlier today https://www.dragos.com/...
  • @kostastsale Kostas on x
    Nobody is immune to attacks. Even Dragos, with all the amazing folks they have there. It only takes one little slip-up. What matters is how many layers of security you have in place to prevent further damage and how you handle the situation. I love the transparency, well done! ht…