Major European utility provider stops insider financial fraud with Unit 42

When the client discovered a disgruntled employee exfiltrated funds, they turned to Unit 42 to neutralize the threat, restore systems, and harden their security posture.

Results
<6hours

to assess exact financial and operational risk from millions of raw application logs.

48hours

to map the attack kill chain and isolate compromised high-value assets.

72hours

to uncover the insider threat, neutralize compromised credentials, and contain the incident.

The Client

A European utilities and energy company that produces and delivers energy to millions of people across the region.

The Challenge

A major European utility provider suffered a financial breach driven by an insider threat. Over a 2-year period, a disgruntled employee secretly planned an attack, ultimately using legitimate access privileges to manipulate payment records and exfiltrate funds to external accounts. Unit 42 was brought in to:

  • Uncover the initial source of unauthorized access to the client's environment and the extent of the intrusion.
  • Identify potential access and exfiltration of data, including personally identifiable information (PII).
  • Provide the client with the indicators of compromise (IoCs) identified during the analysis.
  • Contain and eradicate the threat.

Unit 42’s Rigorous Incident Response Approach for Superior Outcomes

Assess

After detecting an unauthorized intrusion involving manipulated financial transactions and fraud attempts, the client disabled suspicious accounts and brought in Unit 42 to assess the full scope of compromise.

Investigate

Using Cortex XDR, to enable application log correlation, Unit 42 mapped the complete attack chain, identified compromised targets and exposed coverage gaps within 48 hours.

Secure

Removed unauthorized agents installed by the threat actor on 70+ employee workstations, secured the environment and reset compromised accounts.

Recover

Revoked compromised credentials and cleared backdoors to fully restore operations within 3 days.

Transform

Provided hardening recommendations. Replaced legacy tools with Cortex XSIAM® platform.

“Unit 42’s expertise, clear communication, and dedicated support were invaluable throughout our engagement. They gave us confidence when we needed it most and proved to be an exceptional partner during a critical time.”

– CISO

First trigger point

Assess

Investigate

Secure

Recover

Transform

Scroll right

Resolution Timeline

Assess

Investigate

Secure

Recover

Transform

Days 0 - 1
Crisis Intervention

The client engaged Unit 42 after identifying a breach involving manipulated financial transactions and fraud attempts.

Unit 42 discovered the breach was undetected for 2 years and initial access started with VPN connections via the compromised account.

IT team noticed irregular activity, disabled admin accounts and deployed Cortex XDR.

Presented the business impact by correlating SAP security and audit logs.

Days 1 - 2
Investigate

Confirmed account compromise across 70+ user credentials.

Scaled the investigation to fully map the attack chain and identified the threat actor as an internal employee.

Removed agents installed by threat actor on employee workstation and reset all compromised accounts.

Neutralized and remediated backdoors across hundreds of affected workstations and servers.

Days 3
Restoration

Integrated 3rd-party security tech stacks into Cortex XSIAM to enhance central threat visibility and monitoring.

Cleared backdoors and restored all servers and workstations to clean operations within 3 days.

Redesigned and hardened environment infrastructure to eliminate vulnerabilities and prevent future breach attempts.

Days 4 - 10
Fortification

Restored client HR systems to a secure, uncompromised operational state with zero data loss.

Replaced legacy EDR tool and deployed Cortex XSIAM, Prisma® Access and ZTNA enterprisewide.

Last trigger point

Threat-Informed Incident Response

With Unit 42 Incident Response, stay ahead of threats and out of the news. Investigate, contain and recover from incidents faster and emerge stronger than ever before, backed by the full power of the world’s leading cybersecurity company. Contact us to gain peace of mind.

Backed by the Industry’s Best

  • Threat Intel logo icon
    Threat Intel

    Extensive telemetry and intelligence for accelerated investigation and remediation.

  • Technology icon
    Technology

    Palo Alto Networks platform for in-depth visibility to find, contain and eliminate threats faster, with limited disruption.

  • Experience symbol
    Experience

    Trusted experts who mobilize quickly and act decisively in over 1 thousand incidents per year.