Defused A.I CyberSecurity Scoring
Defused
Company Information
Website:https://www.defusedcyber.com
Employees number:3
Number of followers:668
NAICS:541514
Industry Type:Computer and Network Security
Homepage:defusedcyber.com
Defused Risk Score (AI oriented)
Between 700 and 749
DefusedComputer and Network Security
Updated:
03/04/2026
03/04/2026
728/1000
Moderate
Ba
Defused Global Score (TPRM)
xxxx
DefusedComputer and Network Security
Score locked

DefusedModerate
Current Score
728Ba (MODERATE)
01000
1 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
730
MAY 2026
728
APRIL 2026
728
MARCH 2026
728
FEBRUARY 2026
748
Cyber Attack
23 Feb 2026 • Defused
Rolls-Royce, Ericsson, Johnson & Johnson, OPTAGE Inc. and Turkey Ministry of Trade: Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials
Credential-Stuffing Attacks Target Corporate SSO Systems via Infostealer-Mined Logins
727
CRITICAL-21
ERIDEFJOHROLVID1772180734
Credential-Stuffing Attacks Target Corporate SSO Systems via Infostealer-Mined Logins
A surge in credential-stuffing attacks is targeting corporate Single Sign-On (SSO) systems, with recent campaigns focusing on F5 BIG-IP devices. Security firm Defused Cyber analyzed 70 unique email-password pairs used in the attacks, finding that 77% (54 credentials) matched data from Infostealer infections malware like RedLine, Raccoon, and Vidar that harvests browser-saved logins from compromised employee devices.
The attacks, first detected by Defused Cyber’s honeypots, involved malicious authentication attempts from a Japanese IP (219.75.254.166, AS17511, OPTAGE Inc.). Threat actors repurposed stolen credentials to bypass defenses, targeting corporate portals such as ADFS, OWA, and STS, often exploiting weak multi-factor authentication (MFA) enforcement or password reuse.
The campaign highlights an industrialized "log-to-lead" pipeline:
1. Infection: Employees’ devices are compromised by Infostealers, which exfiltrate stored credentials.
2. Marketplace: Stolen logs are sold on underground forums to Initial Access Brokers (IABs).
3. Front-Door Bypass: Attackers use valid credentials to access corporate systems like F5 BIG-IP, leveraging their role in authentication.
4. Network Compromise: Legitimate logins grant direct access, bypassing traditional security measures.
Compromised credentials linked to high-profile organizations were identified, including Rolls-Royce, Johnson & Johnson, Ericsson, Deloitte, Belgian and Queensland Police, Majid Al Futtaim, Cellebrite, Doka, and Turkey’s Ministry of Trade. The attacks cast a wide net, relying on volume to exploit gaps in MFA or user fatigue.
Further investigation revealed the attacks originated from a compromised Fortinet FortiGate-60E firewall hosted by OPTAGE Inc., exposing open ports (541/tcp, 10443/tcp) with a self-signed SSL certificate. This indicates attackers are hijacking network edge devices to launch assaults, turning one organization’s infrastructure into an attack proxy for another.
The campaign underscores a shift in cybercriminal tactics from exploiting vulnerabilities to abusing legitimate authentication emphasizing the growing threat of identity-based attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
748
DECEMBER 2025
748
NOVEMBER 2025
748
OCTOBER 2025
748
SEPTEMBER 2025
748
AUGUST 2025
748
JULY 2025
748
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Defused ??
What was Defused's A.I Rankiteo Cyber Score in May 2026 ??
What was Defused's A.I Rankiteo Cyber Score in April 2026 ??
What was Defused's A.I Rankiteo Cyber Score in March 2026 ??
What was Defused's A.I Rankiteo Cyber Score in February 2026 ??
What was Defused's A.I Rankiteo Cyber Score in January 2026 ??
What was Defused's A.I Rankiteo Cyber Score in December 2025 ??
What was Defused's A.I Rankiteo Cyber Score in November 2025 ??
What was Defused's A.I Rankiteo Cyber Score in October 2025 ??
What was Defused's A.I Rankiteo Cyber Score in September 2025 ??
What was Defused's A.I Rankiteo Cyber Score in August 2025 ??
What was Defused's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Defused's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Defused ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Defused's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?