Help-Desk Resets Became the Entry Point

The weak point was the recovery workflow, not the MFA. If staff will reset passwords and enrolled devices after a phone call, attackers can take over accounts, reach admin access, move data, and even try to launch ransomware without breaking the login system itself. The unsealed complaint ties that path to a May 2025 jewelry retailer breach. Prosecutors say Microsoft device records linked a persistent Windows GDID to the same machine used in the intrusion and then to Peter Stokes, after the attackers stole 77GB and later demanded $8 million.

Part of the PlainSec briefing for 2026-07-08

Editions

Sources