Incident Response

Lateral Movement Examples: 6 Real Breaches

Six public breaches show how vendor access, trusted software, legacy identities, remote portals, and management planes turned entry into impact.

Chris Seymour, Cofounder and Principal at Artemes AI
Chris Seymour
Cofounder, Principal
Sep 8, 2026 11 min read
Six lateral movement breach examples mapped to the trusted pivot and defensive cut point in each incident

The problem is not that defenders lack lateral movement examples. It is that breach reviews retell the entry point and skip the trusted relationship that let the incident spread.

These six cases used different doors: vendor credentials, a software update, a legacy VPN account, remote access without multifactor authentication, two zero day flaws, and password spray. The common failure came after entry. Each actor found a path from the first foothold to systems or data that carried much more consequence.

A useful case study should identify that pivot, the evidence defenders missed, and the control that could have cut the route. Anything less is breach trivia. The goal is to change how your team scopes access, hunts across systems, and verifies containment before the next incident.

Infographic

Six breaches, six pivots defenders could have constrained

Across all six cases, excess trust turned a foothold into a larger incident.

Six lateral movement breach examples and their decisive pivotsA two column matrix shows Target and vendor access, SolarWinds and trusted software, Colonial Pipeline and a legacy VPN identity, Change Healthcare and a Citrix account without multifactor authentication, MITRE and the VMware control plane, and Microsoft with a legacy test tenant. Each pivot maps to one defensive cut point.TargetPivot: Vendor accessCut point: Isolate vendor routesSolarWindsPivot: Trusted softwareCut point: Limit agent reachColonialPivot: Legacy VPN identityCut point: Retire and require MFAChangePivot: Citrix accountCut point: Constrain remote accessMITREPivot: VMware controlCut point: Separate managementMicrosoftPivot: Legacy test tenantCut point: Apply current controlsA breach grows when the next trusted relationship remains usable

What do lateral movement examples teach that technique lists miss?

Technique lists name RDP, SMB, remote services, password reuse, token theft, and administrative tools. Real incidents show why a technique worked in that environment. An HVAC vendor could reach a retailer's internal network. A trusted monitoring product ran with broad privilege. A remote access identity survived after its business purpose faded. Those relationships turned access into impact.

Read each case as a path: entry, usable identity or code, reachable system, privilege, target, and effect. Then ask where the route could have been observed or denied. A lateral movement and attack paths program defines the full operating model. These cases put real consequences behind it.

Public reports always have limits. Some details are confirmed by the affected organization or government investigators. Others remain unknown. Keep those boundaries intact. A sound lesson comes from documented facts, not a tidy story invented after the event.

1. How did vendor access become the Target breach path?

Attackers entered Target's network in November 2013 with credentials stolen from Fazio Mechanical Services, an HVAC and refrigeration contractor. The vendor used remote access for billing, contract submission, and project management. The credentials opened a foothold in a less sensitive part of Target's environment.

The 2014 U.S. Senate staff report on the Target breach found that the attackers moved from that area to systems holding consumer data. Malware reached point of sale terminals, intermediate servers staged stolen data, and security tools produced warnings that did not stop the operation.

Target confirmed exposure of about 40 million credit and debit card accounts and later disclosed theft of personal information for up to 70 million customers. The report put the total affected population as high as 110 million. The decisive pivot was not HVAC technology. It was vendor access that could reach systems far outside the vendor's task.

The cut point is narrow partner access. Give each vendor a named identity, strong authentication, approved source, limited destination, and expiry. Alert when that relationship reaches a new segment or transfers data through an internal staging host.

2. How did SolarWinds turn trusted software into movement?

SolarWinds changed the starting assumption. Victims installed a signed Orion update through a trusted process. The SUNBURST backdoor then gave the actor a foothold inside selected customer environments. Traditional perimeter thinking offered little help because the code arrived through software organizations had approved.

A U.S. Army War College analysis published September 16, 2025 reports that about 18,000 customers received the affected Orion software. Nine federal agencies were confirmed compromised, and the operation ran for roughly nine months before detection. The same analysis covers Colonial Pipeline and Change Healthcare, letting operators compare three different paths instead of treating each breach as a special case.

The pivot was the monitoring system's trusted position and visibility. Software that must observe a large estate can also become a route across it. The cut point is to limit what management software can reach, constrain its service identities, inspect its new outbound behavior, and separate monitoring from identity and recovery control.

3. Why did one Colonial Pipeline identity carry physical consequence?

DarkSide gained access to Colonial Pipeline's business network in May 2021 through a compromised legacy VPN account that lacked multifactor authentication. The War College review reports that attackers stole 100 gigabytes of data within about two hours. Ransomware affected billing and accounting systems, and Colonial stopped pipeline operations while it assessed risk to operational systems.

Public evidence did not show the actor controlling pipeline equipment. The operational effect still became physical because the company could not establish enough confidence in the boundary between compromised business systems and pipeline operations. Uncertainty forced the safer business decision.

The first cut point was mundane: retire unused accounts and require strong authentication on every remote route. The second was architectural: build and test an IT to operations boundary whose state responders can prove under pressure. A diagram is not evidence that traffic and identity cannot cross.

4. What made the Change Healthcare route so damaging?

ALPHV used compromised credentials to enter an older Citrix portal on February 12, 2024. The portal did not use multifactor authentication. The actor moved laterally, escalated privilege, and exfiltrated data before deploying ransomware on February 21. Nine days separated initial entry from the disruptive event.

Change Healthcare sat inside a dense payment and pharmacy network. Disabling affected systems interrupted billing, prescription processing, insurance validation, and provider payments across the United States. The War College analysis reports that notifications eventually covered an estimated 190 million people and that the incident cost UnitedHealth $2.3 billion by its fourth quarter reporting.

The pivot was remote access into an environment with enormous downstream dependence. Multifactor authentication could have challenged the stolen credential, but containment also required narrower internal reach and evidence that distinguished the clearinghouse's business dependencies from administrative paths. The blast radius security guide explains how to map that downstream exposure before an outage makes it visible.

5. How did attackers move through MITRE's NERVE network?

MITRE disclosed in April 2024 that a Chinese state actor compromised its Networked Experimentation, Research, and Virtualization Environment. Its May 24, 2024 investigation summary says the actor used two Ivanti Connect Secure zero day vulnerabilities that bypassed multifactor authentication, then maneuvered inside the network and VMware infrastructure.

This case matters because a strong organization faced an entry method existing controls did not stop. The lesson is not that prevention is pointless. It is that an edge device foothold should not inherit a route to the virtualization control plane. Virtual infrastructure can expose consoles, snapshots, networks, and workloads at once.

The cut point is management separation. Restrict administrative access to approved devices and identities, monitor control plane actions, and prevent an edge appliance from initiating broad management traffic. During response, treat hypervisor access as possible access to every hosted system until evidence narrows the scope.

6. What did Microsoft's legacy test tenant expose?

Midnight Blizzard began a password spray campaign in late November 2023 against a legacy Microsoft test tenant account. According to the Microsoft Security Response Center disclosure from January 19, 2024, the account's permissions let the actor access a small percentage of corporate email accounts, including senior leaders and staff in cybersecurity and legal functions. Microsoft detected the intrusion on January 12.

This was not a product vulnerability. It was a legacy identity operating below current security standards with permissions that reached sensitive information. The actor used the access to collect email and attachments about itself. A forgotten test boundary became a path into current corporate knowledge.

The cut point is control consistency. Inventory nonproduction tenants, remove stale identities, apply the same authentication baseline to every reachable environment, and restrict test accounts from current corporate data. The word test describes purpose. It does not create isolation.

Which patterns repeat across these lateral movement examples?

First, trusted relationships outlived their intended scope. Vendor access reached internal systems. Monitoring software held broad privilege. Old VPN and test identities remained usable. Remote access portals and edge appliances connected to systems with much larger consequence.

Second, the most damaging pivot was often normal administration. Attackers used valid identities, trusted software, internal servers, and management infrastructure. A detection program that alerts only on strange binaries will miss the part of the route that looks like work.

Third, impact expanded through uncertainty. Colonial could not prove the IT and operations boundary. Change Healthcare had to disable connected services. Responders facing an unclear management plane have to assume broad reach. Better architecture reduces both attacker access and the number of systems a cautious responder must isolate.

How can simple math find the dangerous trust relationship?

Count relationships, not accounts. Suppose 20 vendor identities can each reach 50 internal systems. That creates 1,000 identity to system relationships. Limit each vendor to five named systems and the count falls to 100. One access redesign removes 900 relationships, or 90 percent of the possible routes, before any detection rule changes.

Add consequence. If two of those 50 systems manage backups or identities, mark every vendor path to them as serious. Then add evidence age. A route confirmed yesterday deserves a different response from a firewall export collected six months ago. Simple arithmetic will not replace judgment, but it exposes broad trust that asset severity scores ignore.

How should a security team apply these breach lessons?

Pick the six trust categories the cases expose: partners, management software, remote access, identity, virtualization, and nonproduction environments. For each category, name the owner, current source and destination scope, authentication rule, monitoring evidence, expiry process, and containment test.

Hunt for new relationships rather than isolated events. A vendor identity reaching a new segment, a management agent opening a new outbound route, a dormant account authenticating, or an edge appliance contacting a hypervisor should carry more weight than the same event on an approved path. The lateral movement detection guide shows how to join source, identity, channel, target, and action into a reviewable sequence.

Test containment with expected denials. An expired vendor account should fail. A user network should not reach a virtualization interface. A nonproduction identity should not read executive email. Record the policy decision and the resulting telemetry. If nobody can prove the denial, the control exists only on paper.

Deep endpoint context with AI driven analysis can help Artemes connect live system state to the identity and network relationships behind a finding. The operator still needs to own the boundary and verify the result. Good analysis shortens the path from evidence to a safe change.

What should a breach review produce?

Produce a path diagram with documented evidence at each edge. Name the first foothold, every identity used, each system reached, privilege gained, data or control exposed, and the effect. Mark unknowns instead of filling them with assumptions.

Assign one repair to each reusable pattern. The Target lesson belongs to third party access owners. SolarWinds belongs to management plane architects and software risk owners. Colonial and Change belong to remote access and identity teams. MITRE belongs to edge and virtualization owners. Microsoft belongs to tenant lifecycle and data access owners.

End with a validation date. Recheck the old path from the same source class and confirm the expected denial. Keep a detection for the relationship returning. A lesson is learned only when the environment changes and the change survives drift.

Frequently asked questions

What is the most common lateral movement pattern in major breaches?

Valid access crossing a boundary it did not need to cross. The credential, software, or management channel often worked as designed. Its scope was broader than the business task required.

Does multifactor authentication stop lateral movement?

It can block a stolen password at entry, as the Colonial and Change cases show. It does not contain a stolen session, trusted software process, compromised appliance, or overbroad internal permission. Use it with narrow reach and session controls.

Why include old incidents such as Target?

The technology aged. The operating failure did not. Partner identity, weak segmentation, missed alerts, and internal staging still appear in current incidents. An old case remains useful when its path shape still exists in your environment.

How many case studies should a tabletop use?

One case is enough if the exercise maps its decisions to your systems. Use several when comparing different entry paths. Keep the exercise focused on owners, evidence, containment, and recovery rather than breach history.

The executive takeaway

Choose one trust relationship from these cases that exists in your environment today. A vendor route, legacy account, management agent, remote portal, hypervisor, or test tenant. Map what it can reach, remove access it does not need, and test the denial this week. The entry method in the next breach may be new. The broad trust behind the next pivot probably is not.

Artemes AI

Put more evidence behind vulnerability decisions

Artemes AI combines endpoint telemetry, sourced vulnerability intelligence, and analysis with practitioner review so teams can examine the evidence, missing context, and recommended next step together. We are accepting early access requests now.

Chris Seymour, Cofounder and Principal at Artemes AI

Chris Seymour

Cofounder, Principal

Chris writes about vulnerability prioritization, exploitability, remediation supported by AI, and the engineering realities of turning scanner output into remediation decisions.

Lateral Movement
Incident Response
Threat Modeling
Found this useful? Share it.

Get articles like this in your inbox.

Security research and occasional Artemes AI product updates.