Chapter 6
Real threats. Real organisations. Real consequences.
These patterns are representative of documented attacks across industries. They show how infostealer-derived data becomes catastrophic damage — and how earlier visibility changes outcomes.
VPN credentials, $40M ransom
A hospital network shut down after attackers bought VPN credentials from a stealer log. An admin had reused a work email on a compromised gaming platform. Silent VPN access, lateral movement over days, ransomware across thousands of endpoints — surgeries cancelled, records encrypted, $40M paid to recover.
Session hijack, regulatory action
A firm learned only from a regulatory probe that an attacker had used a stolen session cookie for six weeks on an internal portfolio system — harvested from a relationship manager's personal laptop by RedLine. Client data and pre-announcement information exfiltrated; $15M in penalties and major client loss.
Supply chain credential compromise
Attackers entered via a logistics partner's stolen supplier-portal credentials from a contractor device. Production schedules manipulated, IP exfiltrated, persistence near OT-adjacent systems — estimated loss over $200M.