Digital Forensics Incident Response (DFIR)
Home / About Maryman / Case Studies / Digital Forensics Incident Response (DFIR) – Breach of Client information
CASE STUDY
DFIR Case Study for Breach of Client information
Tags
Digital Forensics, Incident Response, DFIR, Breach, Accounting Firm
Background
Scope
Preservation
Working alongside law enforcement, the Maryman team proceeded to triage and preserve all systems, servers, workstations, and email systems within the organization.
Analysis and Findings
Working alongside the IT staff of the firm, it was quickly discovered that the Virtual Private Network (VPN) of the environment had been accessed by an unauthorized individual using stolen credentials. We were able to follow those credentials to the accounting systems and applications, establishing a narrow window for which the compromise occurred. We were able to determine the method that the attackers were able to exfiltrate the filed tax returns of the individuals using the print-to-PDF capabilities, and luckily the accounting system had very detailed logs pertaining to individual activities for individual user accounts.
A triage of the other systems within the organization revealed that no other systems were breached by the attackers. The attack was isolated to only the VPN and the accounting server system.