Netwrix 1Secure delivers unified visibility across data and identity - free for 14 days with full access. Start a free trial

Resource centerBlog

The Largest and Most Notorious Cyber Attacks in History

The Largest and Most Notorious Cyber Attacks in History

Sep 6, 2026

The most damaging cyber attacks in history rarely involved exotic techniques. A graduate student's experimental worm, a password with no second factor, and an unpatched file transfer tool each caused more damage than any advanced exploit on record. Reading four decades of these incidents in order shows how consistently intruders take the simplest available route, and how little that route has changed since 1988.

Cyber attacks are deliberate attempts to steal, alter, or destroy data; disrupt operations; or damage the digital foundations of critical infrastructure. The pattern behind them has narrowed sharply over the past decade, and 75% of incident-based exposures now begin with a compromised identity or a misconfigured permission, according to the Netwrix 2026 Data and Identity Security Report.

Attacks like these are no longer rare, either: 51% of organizations handled one in the past year serious enough to require hands-on work from their security team, not something automated remediation alone could resolve, per the Netwrix Cybersecurity Trends Report 2025.

Four decades of major attacks make the pattern hard to miss once you set them side by side. The Morris Worm, Colonial Pipeline, and Change Healthcare are separated by 36 years and share one shape. A legitimate route in, a stretch of unnoticed movement, then a payload delivered once the intruder already held the access they needed.

This article covers the most destructive attacks on record, what motivated them, what they cost, and which defensive lessons survived contact with reality.

What is a cyber attack?

A cyber attack is a deliberate attempt by an individual, group, or nation-state to gain unauthorized access to computer systems, networks, or data to steal, alter, destroy, or disrupt them. Attackers may pursue money, intelligence, political advantage, or simple disruption, and the same technique often serves several of those ends.

Most attacks unfold in stages rather than a single move. An intruder gains an initial foothold, usually through stolen credentials, a phishing message, or an unpatched vulnerability. Privilege escalation follows, then lateral movement through the network, and finally the objective itself, whether that's exfiltrating data or deploying ransomware. The incidents below repeat that pattern with remarkable consistency.

Types of cyber attacks

Attacks fall into a handful of recognizable categories, though most real incidents combine several types of cyber attacks along a single path, which is why defending against one technique in isolation rarely holds.

  • Malware: Malicious software that infiltrates systems to inflict damage or steal data, covering viruses, worms, and spyware.
  • Ransomware: Malware that encrypts files or systems and demands payment, usually in cryptocurrency, for a decryption key or a promise to restore access.
  • Phishing: Attempts to collect sensitive information by impersonating a legitimate sender, with variants using text messages (smishing), voice calls (vishing), and falsified QR codes (quishing).
  • Social engineering: Exploitation of trust, fear, curiosity, or urgency to make someone reveal information, grant access, or take an action that compromises security.
  • Denial-of-service attacks: Flooding a system or network with traffic until legitimate users can't reach it.
  • Man-in-the-middle attacks: Intercepting communication between two parties to steal data or inject malicious code.
  • SQL injection: Exploiting unvalidated input on a database-driven site to reach data the application should never expose.
  • Zero-day exploits: Using a software or hardware flaw before the vendor has issued a patch.
  • Credential-based attacks: Logging in as a legitimate user with credentials that were stolen, sprayed, or recovered through brute force attacks, now the most common route into an organization.

The combination matters more than any single technique. Phishing harvests valid credentials; those credentials open the front door; a denial-of-service attack occupies the defenders; and a known vulnerability carries the intruder deeper into critical systems.

Phishing remains the most common incident type on both sides of the perimeter, reported by 73% of organizations for cloud environments and 69% on-premises in the Netwrix Cybersecurity Trends Report 2025.

Underlying motivations behind cyberattacks

A handful of motives account for nearly every attack on record, and they overlap more often than they separate.

  • Financial gain: Attackers monetize access by selling personal information, financial data, or intellectual property, demanding ransoms, or manipulating employees into transferring funds.
  • Political or ideological aims: Disrupting services or damaging reputations over political or ideological disagreement, frequently through defacement, leaks, or denial-of-service campaigns.
  • National interest: States target government agencies, defense systems, and critical infrastructure to gather intelligence or degrade an adversary's capability.
  • Corporate espionage: Theft of a competitor's trade secrets, research, or proprietary information, sometimes through intermediaries rather than directly.
  • Ego and reputation: Attackers demonstrating skill, building standing in hacking circles, or testing what they can reach.

Netwrix Threat Prevention blocks DCSync, Kerberoasting, and Pass-the-Hash attacks on Active Directory in real time. Request a demo

The impact of cyberattacks

Damage extends well past the immediate target, reaching communities, economies, and international relations.

The scale is easiest to see in aggregate cost. Cybersecurity Ventures put global cybercrime damage at $3 trillion in 2015 and forecast $10.5 trillion annually by 2025, a figure the World Economic Forum and others have widely adopted. Their current projection reaches $12.2 trillion by 2031.

Financial damage is the easiest impact to count, and rarely the one organizations remember. In the Netwrix Cybersecurity Trends Report 2025, survey respondents reporting financial damage from attacks rose from 60% in 2024 to 75% in 2025, though the operational and reputational costs behind those figures took longer to settle.

Impact on critical infrastructure

Attacks on power grids, hospitals, and water treatment systems create public safety risks beyond data loss, because service outages disrupt daily life and can directly endanger lives. Repeated or severe incidents also erode public trust in the institutions responsible for essential services.

Impact on governments

Theft of classified material such as military intelligence, or damage to defense systems and communication networks, weakens a country's defensive posture. Disruption to government operations can cripple emergency response systems and payments to vulnerable populations. Attacks paired with disinformation campaigns increasingly aim to influence elections, shift public opinion, and create unrest.

Impact on corporations

A breach erodes customer trust and costs revenue, and the damage frequently spreads into partner and supply chain relationships. Theft of trade secrets and research weakens competitive position in ways that take years to surface. Regulatory penalties, litigation, and remediation costs typically exceed the ransom demand by a wide margin.

The special case of cyber warfare

Cyber warfare is the use of digital attacks by a nation-state or by actors working on its behalf to damage, disrupt, or gather intelligence from another state's systems, infrastructure, or institutions. It differs from criminal attacks in objective rather than technique, since the goal is strategic advantage instead of money.

The difference in objective changes the economics of the attack. Nation-states bring budgets, patience, and a tolerance for long dwell times that criminal groups rarely match, and they don't choose targets for financial value. Operations can run for years before producing a visible effect, and the effect itself may be political rather than technical.

The distinction blurs in practice, since states use criminal groups as proxies, criminal groups adopt state-developed tooling once it leaks, and the same malware turns up in both contexts. NotPetya began as a state operation against Ukraine and spread worldwide, causing billions in collateral damage to companies that were never the intended target.

The most notable cyber attacks in history

Attacks have grown more complex, more organized, and more commercial over nearly four decades. Early incidents were largely the work of individuals proving a point. Today's are run by criminal enterprises with support desks and affiliate programs, or by state agencies with strategic objectives.

A timeline of major cyberattacks

The entries below span 37 years, running from a graduate student's experiment that escaped its author to a ransomware attack that halted medical claims processing across the United States. Each one earned its place for a different reason, whether that was scale, novelty, financial cost, or the precedent it set for everything after it.

Year

Attack

Why it mattered

1988

Morris Worm

First widely disruptive internet worm

1994

AOHell

Popularized phishing as a technique

1998

Solar Sunrise

Exposed US defense network vulnerabilities

2000

ILOVEYOU

Email worm causing global damage in hours

2003

SQL Slammer

Fastest-spreading worm recorded

2007

Estonia

First large-scale attack on a nation's infrastructure

2008

Conficker

Botnet infecting millions of machines

2009

Google (Operation Aurora)

State-linked corporate espionage at scale

2010

Stuxnet

First malware to cause physical destruction

2011

RSA Security

Compromise of a security vendor's own tokens

2011

Sony PlayStation Network

Mass consumer data exposure

2013

Yahoo

Largest breach by account count

2014

US Office of Personnel Management

Theft of federal personnel records

2015

Ukraine power grid

First cyber attack to cut electricity

2016

Democratic National Committee

Attack aimed at influencing an election

2017

WannaCry

Global ransomware using leaked state tooling

2017

NotPetya

Costliest cyber attack on record

2017

Equifax

Unpatched flaw exposing credit data

2018

Marriott

Four years of undetected access

2020

SolarWinds

Supply chain compromise reaching government

2021

Colonial Pipeline

Fuel shortages from a single password

2022

Russia-Ukraine

Sustained cyber warfare alongside conflict

2023

MOVEit

Mass exploitation of one file transfer flaw

2024

Change Healthcare

Largest US healthcare breach

2024

Snowflake customer breaches

Credential reuse across many tenants

2025

UK retail campaign

Social engineering against household names

Attacks moved from individual experiments to organized criminal and state operations around the mid-2000s, changing both the resources behind them and the patience with which they were run.

The route in changed as well, away from technical exploitation and toward legitimate credentials obtained by other means. The second shift is still underway, and it accounts for most entries after 2020.

Three of the biggest cyberattacks of all time

Ranking attacks by size depends entirely on what gets measured. The three below take the top position on three different scales, covering how far an attack spread, how many records it exposed, and whether it produced consequences outside a computer at all.

WannaCry (2017)

The WannaCry attack in May 2017 infected individual users and large organizations across more than 150 countries within days, encrypting files and demanding Bitcoin payment.

  • Methodology: The ransomware spread using EternalBlue, an exploit developed by the US National Security Agency and leaked by the Shadow Brokers group. EternalBlue targeted a flaw in the Windows Server Message Block protocol that Microsoft had patched two months earlier, so the damage fell almost entirely on unpatched systems.
  • Response: A security researcher registered a domain found in the malware code, which acted as a kill switch and slowed the spread. Organizations patched, isolated affected machines, and restored from backups where they had them.
  • Impact: The UK's National Health Service was among the hardest hit, canceling thousands of appointments and operations. Estimates of global damage run into billions of dollars.

Yahoo (2013)

A breach at Yahoo exposed data belonging to every one of its accounts, though the full scale took years to emerge and was only disclosed during acquisition talks.

  • Methodology: Attackers used forged cookies to access accounts without passwords, alongside stolen credentials. Yahoo's use of outdated MD5 hashing left many passwords trivially crackable.
  • Response: Yahoo forced password resets and invalidated forged cookies, but disclosed the breach years later.
  • Impact: All 3 billion accounts were affected, making it the largest breach by account count ever recorded. Verizon reduced its acquisition price by $350 million as a result.

Ukraine power grid (2015)

A 2015 attack in Ukraine was the first cyber attack to shut down an electricity grid, leaving roughly 230,000 people without power.

  • Methodology: Attackers used spear-phishing to deliver BlackEnergy malware, harvested credentials over months of reconnaissance, then used legitimate remote access tools to open circuit breakers manually. They also wiped systems and flooded the utility's call center to delay response.
  • Response: Operators restored power within hours by switching to manual control, a capability many modernized grids no longer retain.
  • Impact: Around 230,000 residents lost power for up to six hours. The attack showed that cyber operations can produce physical consequences at a national scale.

NotPetya (2017)

NotPetya caused more global economic damage than any single cyberattack on record, with total costs across every affected company estimated near $10 billion.

  • Methodology: The malware entered through a compromised update to M.E.Doc, Ukrainian tax software, then used a modified Mimikatz to pull Windows credentials from memory and replay them across trusted network segments, combined with the EternalBlue exploit, to spread without any user action.
  • Response: Maersk's roughly 150 domain controllers synced for redundancy, so the malware wiped them all at once, except one in Ghana that had gone offline during a power outage moments before the attack hit. A staffer flew that backup to London by hand; Maersk rebuilt over 4,000 servers and 45,000 workstations from it within ten days.
  • Impact: Maersk alone lost $200–300 million, and its port terminals stopped moving containers for two days. Merck, FedEx's TNT Express division, and several other multinationals suffered comparable losses.

Netwrix Threat Prevention blocks DCSync, Kerberoasting, and Pass-the-Hash attacks on Active Directory in real time. Request a demo

Recent major cyber attacks

The attacks below are the most consequential of the past five years. Read together, they show a clear shift away from clever exploitation and toward stolen credentials, unpatched edge software, and third-party providers whose compromise reaches hundreds of downstream organizations at once.

Change Healthcare (2024)

The February 2024 ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary processing a large share of US medical claims, became the largest healthcare data breach in American history.

  • Methodology: Attackers logged in on February 12, 2024, using stolen credentials on a Citrix remote access portal that had no multi-factor authentication enabled, as UnitedHealth CEO Andrew Witty confirmed in Senate testimony. They operated undetected for nine days before deploying BlackCat ransomware. No vulnerability was exploited to gain entry.
  • Response: UnitedHealth took systems offline, paid a $22 million ransom, and still saw the stolen data leaked. Recovery took months, and providers went unpaid.
  • Impact: Roughly 190 million people had data exposed. UnitedHealth reported total response costs above $2.9 billion, and pharmacies, hospitals, and practices across the country couldn't process claims for weeks.

Change Healthcare best illustrates a pattern running through this entire list. A single account without a second factor gave intruders nine unobserved days and access to the records of more than half the US population.

Snowflake customer breaches (2024)

Beginning in April 2024, attackers reached data belonging to more than 100 customers of the cloud data platform Snowflake, including AT&T, Ticketmaster, and Santander.

  • Methodology: Credentials harvested by infostealer malware, some of them years old, were used against Snowflake customer tenants that had not enabled multi-factor authentication. Snowflake's own infrastructure was not breached. Each affected organization was compromised through its own account.
  • Response: Snowflake and Mandiant issued guidance, and the platform later moved to enforce multi-factor authentication by default for new accounts.
  • Impact: Hundreds of millions of customer records were exposed across the affected tenants, with AT&T alone reporting call and text metadata for nearly all of its wireless customers.

CDK Global (2024)

In June 2024, CDK Global, which supplies dealer management software to car dealerships across North America, was hit by ransomware twice within roughly 24 hours.

  • Methodology: Attackers deployed BlackSuit ransomware against CDK's core dealer management platform. A second intrusion struck while the company was restoring from the first.
  • Response: CDK shut down its systems, and dealerships reverted to pen and paper for sales, service scheduling, and payroll.
  • Impact: Around 15,000 dealerships lost core operations for roughly two weeks, with industry estimates of collective losses running past $1 billion.

UK retail campaign (2025)

Between April and May 2025, a coordinated campaign struck several of the UK's best-known retailers, including Marks & Spencer, the Co-op, and Harrods.

  • Methodology: The Scattered Spider group used social engineering against help desks, persuading staff to reset credentials and bypass authentication controls, then deployed DragonForce ransomware to encrypt virtual machines. The same group used the technique against MGM Resorts in 2023, and the MGM cyberattack followed an almost identical script.
  • Response: Affected retailers suspended online ordering, took systems offline and rebuilt from backups. Recovery for the worst affected extended over months.
  • Impact: Marks & Spencer suspended online sales for several weeks and reported a material hit to profits. The campaign demonstrated that help desk procedures, rather than technical controls, are now a primary target.

MOVEit (2023)

In 2023, a Russian-speaking cybercriminal group called Clop exploited a vulnerability in MOVEit Transfer software to steal data at scale.

  • Methodology: By exploiting CVE-2023-34362 and deploying a web shell named LEMURLOOT, the group ran unauthorized SQL commands, exfiltrated data and then threatened to publish it unless a ransom was paid.
  • Response: Progress Software released patches immediately upon discovery. Organizations were advised to patch, scan for indicators of compromise, and update security configurations.
  • Impact: More than 2,500 organizations were affected, including Amazon, the BBC, British Airways, Shell, and the New York City Department of Education, exposing data belonging to some 60 million individuals.

Colonial Pipeline (2021)

On May 7, 2021, Colonial Pipeline suffered a ransomware attack that disrupted fuel supplies across the US East Coast. The DarkSide group, believed to operate from Eastern Europe, was responsible.

  • Methodology: Attackers gained access using a compromised VPN account password with no MFA enabled, reportedly obtained from a dark web database. They stole 100 gigabytes of data and encrypted business network systems.
  • Response: Operational technology systems were not directly affected, though the company shut down operations as a precaution. Colonial paid roughly 75 Bitcoin, close to $5 million. The decryption tool proved slow, and the Department of Justice later recovered $2.3 million by tracing the Bitcoin wallet.
  • Impact: Colonial supplies nearly 45% of the East Coast's fuel. A shutdown of several days caused widespread shortages and panic buying, and the US government declared a state of emergency.

SolarWinds (2020)

In December 2020, the IT management company SolarWinds was revealed to have shipped compromised software updates to thousands of customers.

  • Methodology: Attackers inserted malicious code into the Orion platform build process, distributing a backdoor through legitimate signed updates. The code lay dormant before selectively beaconing out.
  • Response: SolarWinds issued clean updates, and affected organizations conducted extensive hunts for follow-on activity. Several US agencies launched formal investigations.
  • Impact: Around 18,000 organizations received the compromised update, including US federal agencies. The incident redefined supply chain risk for enterprise software.

Worst cyber attacks in the government and defense sectors

Public sector targets change what a breach costs. There's no revenue to lose and no customers to churn, so the damage registers instead as degraded capability, compromised personnel, and intelligence that stays useful to an adversary for decades. Several of these losses can't be remediated, because a fingerprint or a clearance file can't be reissued.

SQL Slammer (2003)

The SQL Slammer worm was one of the fastest-spreading malware attacks ever recorded, doubling its infected population every few seconds.

  • Methodology: A 376-byte worm exploited a buffer overflow in Microsoft SQL Server and Desktop Engine, for which a patch had existed for six months. Its small size let it spread at extraordinary speed.
  • Response: Organizations filtered the affected port and applied the outstanding patch.
  • Impact: The worm reached most vulnerable hosts within 10 minutes, disrupted ATM networks, grounded flights, and knocked a nuclear plant monitoring system offline.

Russia-Ukraine cyber warfare (2022 onward)

The Russia-Ukraine conflict has been marked by sustained cyber operations running alongside conventional military action.

  • Methodology: Wiper malware, including HermeticWiper and IsaacWiper, targeted Ukrainian government and financial systems, alongside attacks on satellite communications and repeated attempts against energy infrastructure.
  • Response: Ukraine moved critical systems to cloud hosting outside its borders and received substantial support from Western governments and private technology firms.
  • Impact: The conflict established cyber operations as a standing component of modern warfare, with spillover reaching organizations across Europe.

US Office of Personnel Management (2014)

The US OPM suffered one of the most consequential government breaches on record, exposing detailed background investigation records.

  • Methodology: Attackers used stolen contractor credentials to establish access, then moved laterally over an extended period while remaining undetected.
  • Response: OPM overhauled its security program, and the incident drove significant federal cybersecurity policy change.
  • Impact: Records for 21.5 million people were taken, including security clearance applications and 5.6 million sets of fingerprints, creating counterintelligence exposure that can't be undone.

Major corporate breaches

Corporate incidents are where regulators first tested the consequences of breaches at scale. Each of the three below produced a penalty or settlement large enough to shift how boards treat security spending, and in two cases the response cost exceeded anything the attackers gained.

Marriott (2018)

In November 2018, Marriott International disclosed a breach of the Starwood guest reservation database that had gone undetected since 2014.

  • Methodology: Attackers were present in the Starwood environment before Marriott acquired the chain in 2016, and the access persisted through the merger. Due diligence did not surface it.
  • Response: Marriott retired the Starwood database and consolidated onto its own systems.
  • Impact: Up to 383 million guest records were exposed, including passport numbers. The UK Information Commissioner's Office issued a fine of £18.4 million.

Sony PlayStation Network (2011)

Sony's PlayStation Network, one of the world's largest gaming platforms, was taken offline for 23 days after an intrusion.

  • Methodology: Attackers exploited a known application vulnerability to reach a database holding account details stored without adequate encryption.
  • Response: Sony shut the network down entirely, rebuilt its security architecture, and offered affected users identity protection.
  • Impact: 77 million accounts were compromised. Direct costs exceeded $170 million, and the outage became a case study in disclosure timing.

Equifax (2017)

Equifax, one of the largest credit reporting agencies in the US, suffered a breach that exposed the financial identities of nearly half the American population.

  • Methodology: Attackers exploited a known vulnerability in Apache Struts, CVE-2017-5638, for which a patch had been available for two months. An expired certificate meant traffic inspection failed to spot the exfiltration for 76 days.
  • Response: Equifax patched, engaged incident responders, and faced congressional hearings alongside regulatory action.
  • Impact: 147 million people had Social Security numbers and other financial data exposed. Equifax reached a settlement of up to $700 million.

Notable espionage cyber attacks

Both attacks below were run by states rather than criminals, and the difference shows more in preparation than in technique. Aurora ran against at least 20 companies at once. Stuxnet needed four zero-day vulnerabilities, stolen digital certificates, and detailed knowledge of one specific centrifuge model, which is a budget no ransomware crew would approve.

Google, Operation Aurora (2009)

A sophisticated 2009 attack on Google aimed to gather intelligence and access the accounts of human rights activists.

  • Methodology: Spear-phishing delivered a zero-day exploit targeting Internet Explorer, giving attackers access to internal systems and source code repositories.
  • Response: Google publicly disclosed the attack, an unusual step at the time, and later changed its operating position in China.
  • Impact: The campaign targeted at least 20 major companies. Public attribution of state-linked corporate espionage became far more common afterward.

Stuxnet and Iran's nuclear program (2010)

The 2010 Stuxnet attack was the first malware known to cause physical destruction, targeting uranium enrichment centrifuges.

  • Methodology: Stuxnet used four zero-day vulnerabilities and stolen digital certificates to spread, crossing an air gap via USB media, then altered programmable logic controller behavior while reporting normal readings to operators.
  • Response: Iran replaced damaged centrifuges and isolated affected systems. Neither implicated government has confirmed responsibility.
  • Impact: Roughly 1,000 centrifuges were destroyed. Stuxnet proved that code could produce kinetic effects and reset expectations for industrial control system security.

What these attacks have in common

Read in sequence, the same handful of failures recur across four decades and every category of target. The Netwrix survey data matches what the incidents show: 75% of incident-based exposures begin with a compromised identity or a misconfigured permission.

Credentials open more doors than exploits

Change Healthcare, Colonial Pipeline, the Snowflake tenants, and the Office of Personnel Management were all entered with valid logins rather than through a technical breach. In most of those cases, multi-factor authentication wasn't switched on at all. As a result, account compromise has climbed steadily, rising from 16% of cloud incidents in 2020 to 46% in 2025. Enforcing least privilege limits how far a single stolen credential can travel once it works.

Known vulnerabilities do more damage than unknown ones

WannaCry, SQL Slammer, and Equifax all exploited flaws with available patches, and in two of the three cases the patch had existed for months before the attack. Zero-days attract attention because they're novel. The recurring damage comes from patches nobody applied, a scheduling failure rather than a technical one.

Detection gaps turn intrusions into disasters

Attackers went undetected for four years at Marriott, roughly a year at the Office of Personnel Management, 76 days at Equifax, and only nine at Change Healthcare, which still proved plenty. Each window was long enough for an intruder to act, and each would have been visible to audit log management that someone actually reviewed.

Third parties multiply the blast radius

SolarWinds, MOVEit, Snowflake, CDK Global, and Change Healthcare each compromised a single organization to reach hundreds or thousands more. Supplier access now carries the same risk as employee access, and rarely receives the same scrutiny.

Improving cyber attack prevention and response

These incidents point to a short list of controls that would have blunted most of them. Each control below appears in at least three cases as the missing fix.

Prevention

Enforce multi-factor authentication everywhere, especially for remote access, and apply least privilege so accounts have only the rights they need. Patch known vulnerabilities on a defined schedule rather than when convenient, and segment networks so a foothold in one area doesn't open the rest.

Help desk verification deserves the same treatment as any technical control, since the 2025 UK retail campaign walked past technical defenses by targeting the people who reset passwords.

Detection and response

Deploy endpoint detection and response alongside centralized log collection, then monitor the behaviors that precede damage. Encryption is the last step in a ransomware attack, not the first, so ransomware detection that waits for it has already missed the window. Unusual authentication patterns matter most, since techniques like password spraying leave a distinctive signature well before anything is encrypted. Every incident above involved a dwell period during which detection was possible.

An incident response plan needs to exist before you need it, covering containment, communication, investigation, regulatory notification, and recovery. Assign roles in advance, rehearse the plan, and confirm that backups restore rather than assuming they do.

Recovery and government response

Recovery planning should assume ransom payment fails, because in both Change Healthcare and Colonial Pipeline the purchased decryption proved inadequate or the data leaked anyway. A tested restore path is worth more than a ransom negotiation, and organizations often skip testing it. Governments hold additional options including public attribution, sanctions, indictments, and coordinated takedowns, which have measurably disrupted several ransomware operations in recent years.

How Netwrix helps

The failures running through these incidents are specific, and so are the controls that would have interrupted them. Netwrix covers each with a different product rather than one tool claiming to cover them all.

Removing standing privilege

Change Healthcare, Colonial Pipeline, and the Office of Personnel Management were all accessed through an account with more privilege than was required at the moment. The defense is to stop those accounts from existing between uses, so a stolen credential arrives at a door that grants nothing. Netwrix Privilege Secure replaces permanent admin accounts with access created for a specific task and revoked automatically once that task ends.

Shortening the detection window

Marriott ran for four years undetected and Equifax for 76 days, and in both cases the evidence sat in logs that nobody was reading. Closing that gap takes a record of what changed, kept searchable enough that an anomaly surfaces before an outside party reports it. Netwrix Auditor audits changes, configurations, and access permissions across hybrid Microsoft environments, capturing before-and-after values agentlessly so teams can answer who changed what and when.

Blocking Active Directory attack techniques

Once an intruder holds a foothold, Active Directory is usually the next objective, and ransomware in Active Directory is where most of these incidents ended up. Detecting that escalation after the fact rarely helps, because domain-wide access follows within hours. Netwrix Threat Prevention blocks DCSync attacks, Kerberoasting, and Pass-the-Hash in real time, interrupting the step that turns one compromised account into domain control.

Governing service accounts and automation

Service accounts, pipelines, and automation held privilege in most of the environments above and appeared in none of the review cycles. They authenticate constantly, which makes unusual behavior hard to spot at a glance. Netwrix Threat Manager detects anomalous service account behavior and risky privileged activity across hybrid environments, covering the identities that scheduled access reviews consistently miss.

Learn from the attacks before repeating them

Cyber threats keep growing, and attack surfaces keep widening as connected devices proliferate and artificial intelligence becomes embedded in critical systems. Adversaries already use AI to automate reconnaissance and make phishing more convincing, and quantum computing will eventually pressure current encryption.

Even so, the history above argues for something less dramatic than those forecasts suggest. Nearly every attack on this list succeeded through an unenforced control, not an unbeatable technique: an account without a second factor, an unapplied patch, a log nobody read. The organizations that fared best noticed quickly, rehearsed what came next and treated those controls as operational requirements rather than checklist items.

Request a demo to see which of those controls are actually enforced across your own Active Directory and hybrid environment.


Frequently asked questions about the largest and most notorious cyber attacks in history

Share on

Learn More

About the author

Dirk schrader image

Dirk Schrader

VP of Security Research

Dirk Schrader is a Resident CISO (EMEA) and VP of Security Research at Netwrix. A 25-year veteran in IT security with certifications as CISSP (ISC²) and CISM (ISACA), he works to advance cyber resilience as a modern approach to tackling cyber threats. Dirk has worked on cybersecurity projects around the globe, starting in technical and support roles at the beginning of his career and then moving into sales, marketing and product management positions at both large multinational corporations and small startups. He has published numerous articles about the need to address change and vulnerability management to achieve cyber resilience.