Sharing isn’t caring if it’s an admin password: Pwned

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A software development firm's client suffered a full data wipe after sharing the weak password 'admin123' across staging and production environments via a Slack channel. A former contractor used the still-active credentials to trigger the wipe. Despite spending over $30,000 on security tools, the company ignored basic hygiene: shared passwords, no credential rotation, and no access revocation for former contractors. Key lessons include environment-specific credentials, role-based access control, forced credential rotation, MFA, and passkeys where supported.

3m read timeFrom go.theregister.com
Post cover image

Sort: