2021 Malwarebytes — nation-state intrusion via privileged cloud apps (SolarWinds-era reporting)
Data compromised
Selected internal O365 email content and operational metadata described in Malwarebytes’ public reporting
Technical writeup
Malwarebytes disclosed evidence of unauthorized access to a limited subset of internal company emails after Microsoft notified the company of suspicious activity tied to third-party applications with privileged Mailgun access; Malwarebytes published a detailed technical post describing investigation scope.
Root cause
Abuse of third-party application/OAuth integrations with access to email workflows (per Malwarebytes Labs writeup)