They logged in: the fortnight attackers stopped breaking in
A vishing crew compromises CarGurus, Wynn Resorts and Figure without a single exploit. France's national bank registry is read for 16 days with one stolen credential and no MFA. And a CVSS-10 Cisco SD-WAN bypass triggers a federal emergency directive with 48-hour deadlines.
Executive summary
- Attackers logged in rather than broke in. The fortnight's biggest breaches, CarGurus, Wynn Resorts and France's FICOBA bank registry, all began with a valid credential: vishing of SSO logins in the first two, a stolen civil-servant account with no MFA in the third.
- The network perimeter itself became the exploit. A CVSS-10 authentication bypass in Cisco SD-WAN controllers, exploited quietly since 2023, forced CISA to issue an emergency directive giving federal agencies 48 hours to inventory and patch.
- Healthcare paid the availability price. Ransomware closed all 35 University of Mississippi Medical Center clinics for nine days, and healthcare absorbed roughly a third of February's publicly disclosed ransomware incidents.
Key findings
Ransomware shuts all 35 UMMC clinics statewide for nine days
Ransomware detected in the early hours of 19 February took down the University of Mississippi Medical Center's network, including its Epic electronic health record system, closing all 35 clinics across the state and pushing staff to pen and paper. Clinics reopened on 2 March after nine days; UMMC worked with the FBI and CISA and communicated directly with the attackers.
Vishing crew breaches CarGurus, Wynn and Figure without one exploit
An extortion crew published 12.4 million CarGurus records, demanded 1.5 million dollars from Wynn Resorts over roughly 800,000 employee records, and took around a million customer records from Figure Technology Solutions. Every intrusion began the same way: operators posing as IT support on the phone, harvesting SSO credentials and MFA codes. Over 100 organisations have been hit by the wider campaign.
France's national bank registry read for 16 days with one credential
France's Ministry of the Economy disclosed that an intruder used a civil servant's stolen credentials, on an account with no two-factor authentication, to query the FICOBA national bank account registry for 16 days. Data for roughly 1.2 million accounts was viewed, including IBANs, holder names and addresses, from a registry tracking nearly 300 million accounts.
CVSS-10 Cisco SD-WAN bypass triggers emergency directive ED 26-03
CISA, the NSA and international partners published joint guidance on global exploitation of Cisco SD-WAN systems via an unauthenticated authentication bypass granting admin privileges, reportedly exploited since 2023 for long-term persistence. Emergency Directive ED 26-03 gave US federal agencies 48 hours to inventory and patch, a pace private enterprises should mirror for controller-class infrastructure.
Chrome's first exploited zero-day of 2026; UK resilience bill advances
CISA added six KEV entries across the fortnight, including Chrome's first actively exploited zero-day of the year (CVE-2026-2441) and two Roundcube webmail flaws used for initial access. In parliament, the UK Cyber Security and Resilience Bill completed committee stage, expanding scope to managed service providers and tightening incident reporting ahead of expected Royal Assent this year.
The broader pattern
- Identity is the initial-access vector of the fortnight. Vishing of SSO logins and a single un-MFA'd account did more damage than any exploit chain; help-desk verification and phishing-resistant MFA are now frontline controls.
- Network management planes are crown-jewel assets. An SD-WAN controller bypass exploited for years shows the devices that define the perimeter need the same monitoring, patch SLAs and behavioural baselines as the assets behind them.
- Valid-credential intrusions leave behavioural traces, not signatures. A registry account querying 1.2 million records, or an admin logging in from new infrastructure, only surfaces if identity activity is baselined per account.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Inventory and patch Cisco SD-WAN controllers now. CVE-2026-20127 is CVSS 10.0, on KEV, and was exploited for years before disclosure; treat exposure as presumed and hunt retroactively.
Harden the help desk against vishing. Require call-back verification and manager confirmation for any credential or MFA reset; the fortnight's three biggest breaches started with a phone call.
Enforce phishing-resistant MFA on every privileged and registry account. One un-MFA'd civil-servant login exposed 1.2 million bank accounts over 16 days.
Baseline query and export volumes per identity on data-rich internal systems. Valid-credential abuse produces no exploit signature; anomalous per-account volume is the earliest tell.
Rehearse the paper fallback for clinical and operational continuity. UMMC ran 35 clinics on pen and paper for nine days; the plan only works if it has been drilled.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
Every major intrusion this fortnight rode a valid login, not malware. Blacklight baselines behaviour per identity across SSO, SaaS and network management planes, so a help-desk-reset account authenticating from new infrastructure, a registry login querying at 100x its normal volume, or an SD-WAN admin session that matches a KEV exploitation pattern is investigated and contained autonomously, with the full reasoning trail ready for your team.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog and Emergency Directive ED 26-03 (February 2026) · joint CISA/NSA advisory on Cisco SD-WAN exploitation (25 February 2026) · Google Chrome security release notes (13 February 2026) · public breach disclosures and security-press reporting (BleepingComputer, SecurityWeek, The Record, The Register), 16 February – 1 March 2026 · BlackFog State of Ransomware, February 2026 · UK Parliament, Cyber Security and Resilience Bill progress · MITRE ATT&CK v15 for technique mapping.