All chapters

Chapter 6

Real threats. Real organisations. Real consequences.

These patterns are representative of documented attacks across industries. They show how infostealer-derived data becomes catastrophic damage — and how earlier visibility changes outcomes.

Healthcare

VPN credentials, $40M ransom

A hospital network shut down after attackers bought VPN credentials from a stealer log. An admin had reused a work email on a compromised gaming platform. Silent VPN access, lateral movement over days, ransomware across thousands of endpoints — surgeries cancelled, records encrypted, $40M paid to recover.

Financial services

Session hijack, regulatory action

A firm learned only from a regulatory probe that an attacker had used a stolen session cookie for six weeks on an internal portfolio system — harvested from a relationship manager's personal laptop by RedLine. Client data and pre-announcement information exfiltrated; $15M in penalties and major client loss.

Manufacturing

Supply chain credential compromise

Attackers entered via a logistics partner's stolen supplier-portal credentials from a contractor device. Production schedules manipulated, IP exfiltrated, persistence near OT-adjacent systems — estimated loss over $200M.