Industry News: Cyber

Know Your Breach: Axie Infinity

Written by Cybersecurity | Jul 15, 2022 3:05:33 PM

The Target: Axie Infinity, a Decentralized Finance company that runs a “play to earn” game video game.

The Take: $625 million worth of crypto currency.

The Vector: The hackers used social engineering and phishing to craft a highly targeted fake job offer email and embedded a malicious program instead a PDF attachment. The Axie Infinity employee believed this was legitimate and opened the PDF attachment, and during the fake recruiting process, also gave away critical personal information which was then used to gain access to the firm’s systems to steal the funds.

This breach highlights the ongoing and ever-present need for employee training to protect a firm against social engineering attacks. By using the exposed credentials, the attackers were able to act with all the same permissions as the affected employee and pivot into other systems. The human component of cybersecurity is a very real and important piece of the overall picture of cybersecurity posture.

Read more...