“The hackers gained initial access using a stolen account credential that lacked multi-factor authentication security, according to UnitedHealth.”
Absolutely unacceptable. I might be easier to forgive them if some zero day was used, but that’s so easily preventable.
That account presumably had some level of privileges, the policy should have been to enforce MFA, and if the account was inactive, disable it until the user needs it at which point set up MFA again.
I no longer have any complaints about Beszel. Thank you!