What is credential theft?
Credential theft is the stealing of the usernames, passwords, access keys and session tokens that people and systems use to sign in. With a stolen credential an attacker does not need to break anything: they log in as a legitimate user, and from that point their actions look like routine administration.
Restore points deleted with the real administrator's buttons
Backups are the reason an organization can refuse a ransom, so attackers go after them before they encrypt anything. The easiest way in is rarely a software flaw. It is a login. Someone holding the password of a domain administrator, a hypervisor administrator or the backup administrator can open the backup console and delete restore points, shorten retention, disable jobs or wipe the repository, using exactly the same buttons the real administrator uses.
Because every one of those actions is authorized, the backup software has no reason to treat it as an attack. Alerts, if any, read like maintenance. In many incidents the damage comes to light only when the team starts a restore and finds nothing usable to restore from.
Phishing, password reuse and keys left in scripts
- Phishing and fake login pages that capture a password and the one-time code typed alongside it.
- Malware on an administrator's workstation that records keystrokes or copies passwords saved in the browser.
- Password reuse: credentials leaked from another service tried against VPN, email and management consoles.
- Keys left in plain sight: S3 access keys and API tokens in scripts, configuration files, job definitions or code repositories.
- Help desk manipulation: a caller convinces support staff to reset a password or register a new MFA device.
Once inside, attackers harvest further credentials from each system they reach, working their way toward the accounts that control virtualization, identity and backup.
Damage by stolen account type
| Credential | What a stolen copy allows |
|---|---|
| Standard user account | Reading and encrypting the files and shares that user can reach |
| Domain administrator | Signing in to most servers, including any backup server joined to the domain |
| Hypervisor or vCenter administrator | Deleting snapshots and virtual machines, including a virtualized backup server |
| Backup software administrator | Deleting restore points, changing retention, disabling or redirecting jobs |
| Storage administrator or S3 access key | Deleting or overwriting the stored backup data directly, bypassing the backup software |
The more systems a single account reaches, the more an attacker can destroy with it. That reach is the administrative blast radius of the account.
One domain password reaching every copy
In many small and mid-sized IT teams the same few administrators run production, virtualization and backup, often with one set of domain accounts. The backup server is joined to the domain for convenience, the repository is reachable from the same network, and the S3 keys the backup software uses have full rights to the bucket. In that layout one stolen domain password reaches every copy of the data at once.
A sounder way to judge a backup design is to assume that some administrator credential will eventually be stolen, then ask what still survives. Copies that depend only on access control last only as long as the credentials do. Copies protected by retention that the storage itself enforces, which no account can shorten, survive regardless of whose password was taken. That difference decides whether recovery is possible without paying.
ARTESCA and credential theft
ARTESCA keeps its own accounts, separate from the production directory, so a stolen domain administrator password does not unlock the backup storage. Its IAM-style access model lets the backup application's keys be confined to specific buckets and actions rather than full control of the system.
For backups protected by S3 Object Lock in compliance mode, no account, root included, can delete them or shorten their retention before the retain-until date. A stolen ARTESCA administrator credential therefore cannot erase protected restore points either. Governance mode offers no such protection, since any identity holding the bypass permission can lift it. None of this stops the phishing page or keylogger that captures a password; ARTESCA limits what the stolen login can reach once it is used.
Related terms
- Administrative blast radius: the total set of systems one admin identity can change or wipe.
- Backup tampering: an attacker quietly altering or deleting backups and their settings.
- Insider threat: damage done through access that was legitimately granted.
- Zero trust security: checking every access request instead of trusting the network it came from.
