2023 LogicMonitor — weak default setup passwords; customer account / Collector abuse and ransomware follow-on
Data compromised
Customer-network systems and monitoring-scope assets per victim orgs—no standardized public individual tally
Technical writeup
LogicMonitor confirmed August 2023 activity in which adversaries guessed or reused predictable initial passwords for a limited set of customer accounts, then leveraged on-prem Collectors to stage ransomware in some environments. TechCrunch and BleepingComputer tied the pattern to mandatory first-login password changes introduced after the incident; impact is inherently customer-tenant-specific rather than a single global user count.
Root cause
Predictable default or initial account passwords on customer tenants plus privileged Collector execution paths