The Containment Era is here. →Explore

Executive Summary

In May 2026, the cybercriminal collective known as 'The Com' orchestrated a series of sophisticated cyberattacks targeting cloud environments and SaaS platforms of major organizations. These breaches resulted in significant data exfiltration and operational disruptions. The Com, comprising subgroups like Scattered Lapsus$ Hunters, utilized advanced social engineering tactics, including vishing campaigns, to infiltrate IT helpdesks and gain unauthorized access to sensitive systems. The financial gains from these cybercrimes were reportedly funneled into supporting violent activities and the exploitation of minors, highlighting the broader societal impact of such security breaches.

This incident underscores the evolving threat landscape where cybercriminal groups are increasingly targeting cloud infrastructures and leveraging social engineering to bypass traditional security measures. Organizations must enhance their security protocols, particularly around identity verification and access controls, to mitigate the risks posed by such sophisticated threat actors.

Why This Matters Now

The Com's recent cyberattacks highlight the urgent need for organizations to fortify their cloud security and educate employees on advanced social engineering tactics, as these breaches have far-reaching consequences beyond financial loss, including supporting violent crimes and exploitation.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The Com employed advanced social engineering tactics, including vishing campaigns targeting IT helpdesks, to gain unauthorized access to cloud environments and SaaS platforms.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access may have been limited by reducing the exposure of misconfigured services through embedded security controls.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been constrained by limiting access to critical resources through identity-aware segmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement within the cloud environment could have been limited by enforcing east-west traffic controls, reducing the attacker's ability to traverse the network.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The establishment of command and control channels could have been constrained by providing comprehensive visibility and control over multicloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts may have been limited by enforcing strict egress policies, reducing the attacker's ability to transfer data externally.

Impact (Mitigations)

The deployment of ransomware may have been limited by reducing the attacker's access to critical systems and data through enforced segmentation.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management (CRM)
  • Sales Operations
  • IT Help Desk
  • Data Security Compliance
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Personal Identifiable Information (PII) of customers, including names, email addresses, and contact details; sensitive corporate data such as sales records and internal communications.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within cloud environments.
  • Enforce Multi-Factor Authentication (MFA) for all IAM roles to prevent unauthorized access.
  • Utilize Cloud Firewall (ACF) to monitor and control egress traffic, preventing data exfiltration.
  • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious activities.
  • Regularly audit and remediate misconfigurations in cloud services to eliminate initial access vectors.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image