One Valid Account, One External Door: What CISA Incident Data Teaches Us
Attackers do not always need to break in. Sometimes they authenticate.
CISA incident-response reporting has repeatedly documented the use of valid accounts against external remote services. In one published case, accounts without MFA were used to access a VPN; CISA did not establish how the credentials had originally been acquired.
That is the right way to read incident evidence: separate what is known from what is assumed. The strategic takeaway is still clear. Every public login surface is part of the identity attack surface, including legacy VPNs, webmail, remote administration, SSO, and supplier portals.
Ask four questions: Is the service still required? Is MFA enforced for every route? Who owns the account population? Can the service be reached from the public internet?
If any answer is unclear, you do not have a configuration issue. You have an exposure-management issue.
Access is not only an identity decision. It is a reachability decision.
TUT1 helps teams map domains, live services, identity-related exposure signals, and ownership gaps so external doors can be validated before they become an incident.
Primary topic · valid accounts MFA