Extensive telemetry and intelligence for accelerated investigation and remediation.
Unit 42 Stops Silent Attack on Tech Leader and Reduces Ransom by 70%
A complex cyberattack leading to 42 days of silent compromise prompted the client to bring in Unit 42® to investigate, contain, and rebuild the compromised network.
The Client
A Fortune Global 500 manufacturing technology company headquartered in Asia with subsidiary companies around the world.
The Challenge
The client was facing a multifaceted cyberattack involving Akira ransomware, a cloud breach, data theft, and extortion. Compounding the incident was the failure of its deployed EDR solution to alert on malicious activity — despite logging the events — and the lack of response by its existing IR firm. It was also dealing with lateral movement across its manufacturing and corporate domains, and the deletion of critical cloud assets. Unit 42 came in to help:
- Perform forensic investigation and contain the incident.
- Eradicate the threat actor from the environment.
- Negotiate terms with the threat actor and understand the data at risk.
- Get the client’s network back up and running in a secure manner, rebuild systems to a clean state, and reduce the attack surface through onboarding Cortex XSIAM® and Prisma® Access.
Unit 42’s Rigorous Incident Response Approach for Superior Outcomes
Threat-informed Incident Response
With Unit 42 Incident Response, stay ahead of threats and out of the news. Investigate, contain and recover from incidents faster and emerge stronger than ever before, backed by the full power of the world’s leading cybersecurity company. Contact us to gain peace of mind.
Backed by the Industry’s Best
- Threat Intel
- Technology
Palo Alto Networks platform offers in-depth visibility to find, contain and eliminate threats faster, with limited disruption.
- Experience
Trusted experts mobilize quickly and act decisively in over 1K incidents per year.