The Containment Era is here. →Explore

Executive Summary

In early 2024, FinWise, a financial services provider, suffered a significant data breach traced to an insider threat that circumvented internal security controls. The attacker exploited inadequate encryption of sensitive data in transit, extracting customer records via lateral movement across poorly segmented network segments. Because traffic was not properly encrypted, packet sniffing allowed the attacker to collect financial and personal data largely undetected for several weeks. The breach led to loss of confidential information, potential regulatory scrutiny, and reputational harm for FinWise.

This incident highlights a rising wave of insider threats exploiting deficiencies in east-west traffic security and underscores the importance of robust, end-to-end encryption as regulatory bodies tighten requirements for securing data in transit and at rest across hybrid and multi-cloud environments.

Why This Matters Now

As organizations face increasingly sophisticated insider threats, relying solely on perimeter defenses is no longer sufficient. This breach underscores the urgency for end-to-end encryption, zero trust segmentation, and continuous traffic monitoring, as both attackers and regulators focus on internal controls and data protection standards.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Key gaps included inadequate encryption of data in transit, insufficient east-west traffic controls, and lack of robust insider monitoring, exposing critical data to unauthorized access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Granular network segmentation, strong east-west and egress controls, and pervasive encryption would have limited the attacker's ability to move laterally, exfiltrate data, or cause significant impact. Zero Trust principles, enforced through CNSF-aligned controls, disrupt kill chain progression even in cases of initial compromise.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Suspicious authentication or access attempts would be rapidly detected and investigated.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Unauthorized privilege escalations are blocked or isolated via strict identity-based segmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Internal movement is detected and thwarted by restricting uncontrolled east-west communication.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Malicious C2 channels are detected and blocked in real time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized outbound data transfers are stopped or flagged before reaching external destinations.

Impact (Mitigations)

Data remained unreadable even if exfiltrated, minimizing breach impact.

Impact at a Glance

Affected Business Functions

  • Customer Service
  • Loan Processing
  • Compliance and Legal
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

The breach exposed sensitive personal information of approximately 689,000 individuals, including full names, dates of birth, Social Security numbers, and account numbers. This exposure increases the risk of identity theft and financial fraud for the affected individuals.

Recommended Actions

  • Implement end-to-end encryption for all sensitive data in transit and at rest to neutralize potential data theft.
  • Enforce strict zero trust segmentation between workloads, identities, and environments to reduce lateral movement risk.
  • Deploy comprehensive east-west and egress filtering with centralized visibility for all traffic flows in multi-cloud and hybrid networks.
  • Integrate inline intrusion prevention and anomaly detection to actively hunt for and respond to covert attacker activity.
  • Regularly audit access policies and privilege assignments, ensuring least privilege is maintained and all sensitive assets are protected by identity-driven controls.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image