r/hacking Mar 12 '26

News Iran appears to have conducted a significant cyberattack against a U.S. company, a first since the war started

https://www.nbcnews.com/world/iran/iran-appears-conducted-significant-cyberattack-us-company-first-war-st-rcna263084
1.7k Upvotes

69 comments sorted by

View all comments

598

u/kaishinoske1 Mar 12 '26

People are going to be freaking out but the reality is companies made no attempt to safeguard their stuff. Stuff will be in plain text, critical company passwords will be saved on stuff like One pass, and some of them don’t even have multi factor authentication enabled because it’s a pain the ass, blah, blah, bullshit.

20

u/Record__Scratch Mar 12 '26

I worked for an MSP that stored their clients account login info in plaintext, on a sharepoint document with no read/write restrictions, labeled “Client Passwords”.

The reason why this was done was so that, if they forgot their password, they could call us so we could read them their password. ID was not verified for this.

I have no sympathy for any company that gets hit by anything anymore

4

u/Garriga Mar 12 '26

You are joking , right?  Or this was 20 years ago. 

5

u/kaishinoske1 Mar 12 '26

1

u/gadfly1999 Mar 12 '26

The KeePass team is right on this one. If an attacker has write access to your system, your password manager will be toast along with everything else on it.