A Single Click Cost One Company $188 Million
In 2020, Marriott disclosed its second major breach in two years — this time exposing 5.2 million guest records. The root cause? Compromised employee credentials at a franchise property. Two employees' login details were used to access data for weeks before anyone noticed. The UK's Information Commissioner's Office hit Marriott with an £18.4 million fine. That's what a single credential theft incident looks like at scale.
If you're searching for cybersecurity incident examples, you're probably trying to understand what real attacks look like, how they unfold, and what your organization can learn from them. I've spent years dissecting these cases, and the patterns are remarkably consistent. Most of the devastating breaches I've studied didn't involve sophisticated zero-day exploits. They involved human error, poor credential hygiene, and missed warning signs.
This post walks through the incidents that actually reshaped cybersecurity practices — with specific lessons you can apply today.
What Qualifies as a Cybersecurity Incident?
A cybersecurity incident is any event that compromises the confidentiality, integrity, or availability of an information system or the data it holds. That includes unauthorized access, ransomware deployment, phishing-driven credential theft, insider threats, and denial-of-service attacks.
Not every incident becomes a breach. But every breach starts as an incident someone failed to catch early enough. The Cybersecurity and Infrastructure Security Agency (CISA) maintains detailed guidance on incident classification and response — it's worth bookmarking.
The SolarWinds Supply Chain Attack: Trust as a Weapon
In December 2020, FireEye disclosed that a threat actor had compromised SolarWinds' Orion software update mechanism. The attackers — later attributed to a nation-state group — embedded malicious code into legitimate software updates that were distributed to roughly 18,000 organizations, including multiple U.S. federal agencies.
This wasn't a phishing email or a brute-force attack. The adversary weaponized the software supply chain itself. Organizations that followed best practices and promptly installed vendor updates were the ones who got compromised.
What This Incident Actually Taught Us
SolarWinds accelerated the adoption of zero trust architecture across the federal government. Executive Order 14028, signed in May 2021, mandated zero trust principles for federal agencies precisely because of this incident. The lesson for your organization: implicit trust in any vendor, software, or network segment is a vulnerability.
Colonial Pipeline: Ransomware Hits Physical Infrastructure
In May 2021, the DarkSide ransomware group shut down Colonial Pipeline, which supplies approximately 45% of the East Coast's fuel. The attack vector was a single compromised VPN credential — an account that didn't use multi-factor authentication.
Colonial paid a $4.4 million ransom (the DOJ later recovered about $2.3 million of it). But the real cost was the panic buying, fuel shortages, and the stark demonstration that cyber attacks have physical consequences.
The MFA Failure That Shut Down Fuel Supply
I've talked to security professionals who use this incident in every board presentation. One dormant VPN account without MFA gave attackers a direct path into the network. If your organization still has legacy accounts without multi-factor authentication, you're carrying the same risk Colonial Pipeline did. Audit your access controls now, not after an incident.
The $4.88M Lesson Most Organizations Learn Too Late
According to IBM's 2024 Cost of a Data Breach Report, the global average cost of a data breach reached $4.88 million. That figure includes detection, escalation, notification, lost business, and post-breach response costs. But here's the number that should concern you most: breaches involving stolen or compromised credentials took an average of 292 days to identify and contain.
Nearly 10 months. That's how long a threat actor can operate inside your environment when the entry point is a compromised password.
This is why cybersecurity awareness training for your workforce isn't optional — it's the control that reduces the longest and most expensive attack vector.
MGM Resorts 2023: Social Engineering in Under 10 Minutes
In September 2023, the Scattered Spider group took down MGM Resorts' operations for roughly 10 days. The attack started with a phone call. The attackers found an employee's information on LinkedIn, called the IT help desk, and socially engineered a credential reset. Within minutes, they had access.
The estimated financial impact exceeded $100 million. Slot machines went dark. Hotel room keys stopped working. Reservation systems collapsed.
Why Phishing Simulations Alone Aren't Enough
MGM's incident wasn't email phishing — it was social engineering via voice (vishing). Most organizations run email-based phishing simulations but never test their help desk verification procedures. If your identity verification process for password resets relies on information available on social media, you're vulnerable to the same attack. Comprehensive phishing awareness training for organizations needs to cover vishing, smishing, and pretexting — not just suspicious emails.
Change Healthcare 2024: When a Breach Affects an Entire Industry
In February 2024, the ALPHV/BlackCat ransomware group hit Change Healthcare, a subsidiary of UnitedHealth Group that processes roughly one-third of all U.S. healthcare claims. The attack disrupted billing, prescriptions, and claims processing for hospitals, pharmacies, and clinics nationwide for weeks.
UnitedHealth Group's CEO testified before Congress that the attackers used compromised credentials to access a Citrix remote access portal that lacked multi-factor authentication. The same pattern as Colonial Pipeline. The reported ransom payment was $22 million.
The Credential Theft Pattern You Can't Ignore
Look at the pattern across these cybersecurity incident examples: Marriott, Colonial Pipeline, MGM, Change Healthcare. Every single one traces back to credential compromise. Not sophisticated malware. Not zero-days. Credentials. The Verizon 2024 Data Breach Investigations Report confirmed that stolen credentials remain the top initial access vector, involved in over 40% of breaches.
MOVEit Transfer 2023: The Vulnerability That Hit Thousands
In May 2023, the Cl0p ransomware group exploited a zero-day SQL injection vulnerability in Progress Software's MOVEit Transfer application. The campaign compromised over 2,600 organizations and exposed data on more than 77 million individuals, according to tracking by Emsisoft.
Victims included the BBC, British Airways, the U.S. Department of Energy, and hundreds of other organizations. Many didn't even know they used MOVEit — it was embedded in their vendors' infrastructure.
Third-Party Risk Is Your Risk
MOVEit reinforced something I've been telling clients for years: your security posture includes every vendor that touches your data. If you're not conducting vendor security assessments and maintaining a software bill of materials, you're flying blind. NIST's Cybersecurity Framework provides a structured approach to managing this supply chain risk.
Common Threads Across Every Major Incident
After reviewing dozens of cybersecurity incident examples over the past decade, I see the same failures repeated:
- Missing multi-factor authentication on critical systems and remote access portals
- Dormant or over-privileged accounts that no one audits
- Employees untrained in social engineering recognition — not just email phishing, but phone and text-based attacks
- Slow detection — threat actors operating undetected for weeks or months
- Third-party access treated with the same trust as internal systems
None of these are exotic problems. They're fundamentals. And they're the fundamentals that keep costing organizations millions.
What Your Organization Should Do Right Now
You don't need to wait for your own incident to learn from these. Here's what I recommend based on the patterns above:
- Enforce MFA everywhere — especially VPNs, remote access tools, and privileged accounts. No exceptions for legacy systems.
- Run realistic security awareness training that covers vishing, pretexting, and business email compromise. Start with a comprehensive cybersecurity awareness program that goes beyond checkbox compliance.
- Audit dormant accounts quarterly. If an account hasn't been used in 90 days, disable it.
- Test your help desk with social engineering scenarios. Can someone call in, impersonate an employee, and get a password reset?
- Map your third-party data flows. Know which vendors handle your data and how they secure it.
- Deploy phishing simulations that evolve. Static, predictable tests don't build real resilience. Use phishing simulation training designed for real-world threat scenarios.
The Incidents Will Keep Coming — Your Response Doesn't Have to Be Reactive
Every cybersecurity incident example I've covered here shares a common truth: the defenders had the tools and knowledge to prevent the breach before it happened. They just didn't apply them consistently. MFA existed. Training was available. Account audits could have been scheduled.
The FBI's Internet Crime Complaint Center (IC3) reported over $12.5 billion in cybercrime losses in 2023. That number grows every year. The attackers aren't getting dramatically more sophisticated — they're exploiting the same gaps organizations keep leaving open.
Your job isn't to build an impenetrable fortress. It's to close the gaps that real threat actors actually exploit. The incidents above show you exactly where those gaps are. The question is whether you'll act on them before your organization becomes the next case study.