✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Management Consulting
Breach intelligence, attack campaigns, and threat reports targeting the Management Consulting sector.
Explore Other Sectors
Management Consulting Threat Reports
BRG Ransomware Breach: How a 2025 Attack Unveiled Legal Sector’s Vendor Risk
In March 2025, Berkeley Research Group (BRG), a prominent consulting and legal advisory firm, suffered a devastating ransomware attack attributed to the RansomHub cybercriminal group. Attackers leveraged persistent dwell time to infiltrate BRG’s network, exfiltrated sensitive data including M&A intelligence and confidential client materials, and encrypted key systems. The breach occurred during BRG's $700 million buyout by TowerBrook Capital Partners, amplifying the incident’s impact and resulting in exposure of information related to hundreds of active deals and thousands of individuals. The attackers’ extortion included threats of blackmail and public data leaks, leveraging their knowledge of both firm structure and sensitive client engagements. This attack spotlights a surge in professional services sector targeting—especially legal and advisory firms—by highly organized ransomware groups in 2024–2025. Threat actors like RansomHub have adopted prolonged infiltration tactics, optimized affiliate compensation, and leveraged industrialized extortion, mirroring broader ransomware trends and underscoring urgent vendor risk management needs.
6 months ago
Kill Chain
Dentsu Subsidiary Employee Data Stolen in 2024 Breach: What Enterprises Must Know
In June 2024, a subsidiary of global marketing and PR giant Dentsu experienced a significant data breach in which unidentified threat actors accessed and stole sensitive employee information. The breach reportedly targeted internal personnel data, potentially exposing names, contact information, and other personally identifiable details, though Dentsu has not publicly shared whether client data was affected. The precise entry vector has not been disclosed, but the attack highlights vulnerabilities in east-west traffic inspection and data-in-transit encryption within subsidiary environments. Dentsu's management responded by initiating a comprehensive forensic investigation and notifying affected employees while enhancing internal security protocols. This breach accentuates the growing targeting of large holding companies and their subsidiaries, as attackers increasingly seek weak links in global enterprise ecosystems. With regulatory pressure mounting and privacy violations facing stiffer penalties worldwide, all large organizations must urgently reassess how they secure internal traffic and control access across decentralised operational units.
6 months ago
Kill Chain
Red Hat Consulting Breach 2024: Crimson Collective Launches Major Supply Chain Attack
In April 2024, the Crimson Collective, in collaboration with elements of the Lapsus$ group, executed a supply chain attack targeting Red Hat Consulting by breaching its GitLab instance. The attackers gained unauthorized access through credential compromise and lateral movement across internal infrastructure, successfully exfiltrating sensitive source code and internal communications. The breach, which remained undetected for several days, raised concerns over east-west traffic security, lack of segmentation, and insufficient anomaly detection within Red Hat Consulting’s cloud development supply chain. This incident highlights the increasing prevalence of supply chain attacks leveraging lateral movement and sophisticated alliance between threat groups. Its relevance is underscored by renewed regulatory scrutiny, the growing risk posed by collaborative cybercriminal operations, and heightened demand for zero trust architecture and cloud-native threat mitigation strategies.
6 months ago
Kill Chain
Red Hat's 2025 Consulting GitLab Breach: Crimson Collective Breaches Development Data
In October 2025, Red Hat, an IBM subsidiary, confirmed a data breach after the Crimson Collective threat group accessed and exfiltrated information from a self-managed GitLab Community Edition instance used for the company’s consulting projects. Attackers reportedly stole over 28,000 code repositories containing project specifications, code samples, internal communications, and potentially sensitive artifacts such as credentials and configuration data shared with consulting customers. The incident did not impact any other Red Hat services or products, and the company promptly launched an investigation, isolated the affected system, and notified relevant authorities and affected customers. This breach highlights growing risks associated with supply chain exposures, particularly when attackers target development and collaboration platforms where sensitive operational data may be stored. The incident is indicative of rising threats from organized cybercrime groups seeking intellectual property, credentials, and internal communications for downstream exploitation.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports