

Unmasking a bad actor at an individual level will help organizations gain more context, figure out why the attack happened, and calculate future risks.
Threat actors have been selling employee credentials and private access keys to critical business applications in increasing numbers.
To prevent these types of incidents from escalating into full-fledged breaches that damage the company’s credibility, organizations need to understand that they must respond quickly to maintain visibility outside their perimeter. External threat hunting, forensics, and the unmasking of actors using open-source information are common actions (OSINT).
Identifying the actor goes a long way toward deciding whether the organization is a target of opportunity or a victim of a targeted attack.
Organizations should, however, take the following three measures to ensure the integrity, confidentiality, and availability of data systems.
Internal and External Triage
Maintaining the integrity, confidentiality, and availability of data systems should be the top priority. This can be accomplished by identifying the source of leaked credentials. If a third-party vendor or law enforcement initiates contact, they can keep those user credentials or private keys when interacting with the threat actor directly.
Unmasking Attribution
Unmasking the hacker at an individual level can help gain more insight, assess why the attack happened, and measure potential danger if the company is a victim of a targeted attack rather than a target of opportunity. Making the decision does not have to be a time-consuming process
Full article: Three Strategies for Organizations to Follow to Disrupt Cybercriminals Selling Access to Their Environment





