Breach investigation & client leadership

When training videos expose administrator credentials

Led a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.

Growing MSSP with Offensive ServicesEnd-to-end incident and client lead; code-review support; remediation handed to the client2 min read

Several websites connected to a shared management portal where uploaded training videos exposed administrator credentials. An attacker had accessed and downloaded sensitive personal material, including driving licences and private photographs. I handled the case and the client engagement end to end.

I reviewed logs for root-cause analysis and to understand the attacker’s access. The investigation brought together the credential exposure, the management portal and the personal data accessed, so the client could understand the technical problem and its consequences.

I connected the investigation to follow-up assessment and hardening: MFA, stronger password requirements, penetration testing and code review. I used additional support for the code review while retaining responsibility for the case and client communication.

I handed remediation to the client, with the findings and follow-up actions needed to address the exposure. My role combined incident investigation with application-security review and a clear handover of the work the client needed to implement.

Methods, evidence & technical decisions

Recognise the shared point of compromise

Several websites connected to the same parent management portal. Training videos held in that portal exposed administrator credentials. The investigation therefore had to consider the shared administrative access behind the websites, alongside the attacker’s access to sensitive personal data.

Open this detail ↗
Reconstruct attacker access from the logs

I reviewed the available logs for root-cause analysis and to understand the attacker’s access. The incident involved access to and download of driving licences and private photographs. Connecting the access evidence with the shared management portal gave the client a clearer account of the exposure and its consequences.

Open this detail ↗
Turn investigation findings into a client remediation plan

Follow-up assessment and hardening covered MFA, stronger password requirements, penetration testing and code review. I brought in additional support for the code review, retained responsibility for the case and client communication, and handed remediation to the client for implementation.

Open this detail ↗

Skills used in this work

This work connects to

SOC & incident responseSecurity engineering & assurance

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.