Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Microsoft Entra Community

Microsoft Entra Community Vendor Cyber Rating & Cyber Score

microsoft.com

Meet the family of multicloud identity and access products. Get access to resources such as articles or live events. Engage with Microsoft #Entra Engineering teams and peers in the group; discover blogs, webinars, videos, events, and more


MEC A.I CyberSecurity Scoring

MEC
Company Information
Website:https://www.microsoft.com/en-us/security/business/microsoft-entra
Employees number:5
Number of followers:20,070
NAICS:5112
Industry Type:Software Development
Homepage:microsoft.com
MEC Risk Score (AI oriented)
Between 0 and 549
logo
MECSoftware Development
Updated:
19/05/2026
474/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MEC Global Score (TPRM)
xxxx
logo
MECSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MEC
MECCritical
Current Score
474C (CRITICAL)
01000
4 incidents
-62.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
482Before Incident
MAY 2026
496Before Incident
Cyber Attack
19 May 2026MEC
Microsoft: Hackers Abuse Microsoft Entra ID Accounts to Exfiltrate Microsoft 365 and Azure Data

Storm-2949 Exploits Microsoft Entra ID in Large-Scale Cloud Data Theft Campaign

475After Incident
CRITICAL-21
MIC1779208971
Storm-2949 Exploits Microsoft Entra ID in Large-Scale Cloud Data Theft Campaign A sophisticated cloud attack campaign by the threat actor Storm-2949 has targeted Microsoft Entra ID accounts, enabling large-scale data theft from Microsoft 365 and Azure environments without relying on traditional malware. The campaign, uncovered recently, highlights a shift in attacker tactics abusing legitimate cloud management tools to infiltrate and exfiltrate sensitive data across SaaS, PaaS, and IaaS layers. ### Attack Execution Storm-2949 gained initial access through social engineering, exploiting Microsoft’s Self-Service Password Reset process. Attackers impersonated IT support staff, tricking users into approving fraudulent multi-factor authentication (MFA) prompts. Once approved, they reset passwords, removed existing authentication methods, and registered their own devices, locking out legitimate users. After establishing a foothold, the attackers used custom Python scripts and Microsoft Graph API queries to enumerate privileged accounts. They then targeted OneDrive and SharePoint, bulk-downloading sensitive files, including VPN configurations and remote access procedures. ### Azure Compromise & Lateral Movement With compromised accounts holding privileged Azure RBAC permissions, Storm-2949 moved into Azure environments, targeting: - Key Vaults (extracting database credentials and secrets) - Storage accounts (manipulating access settings to generate Shared Access Signature tokens) - SQL databases (altering firewall rules to enable unauthorized access) - Azure Virtual Machines (deploying VMAccess extensions to create backdoor admin accounts and installing ScreenConnect after disabling Microsoft Defender) The attackers exfiltrated large volumes of data over several days, then cleared Windows event logs and removed forensic artifacts to evade detection. ### Impact & Indicators of Compromise (IoCs) The campaign demonstrates how threat actors now prioritize cloud identities and control-plane access over device-level exploits. Microsoft’s report confirms the attackers’ focus on high-value assets, including IT staff and senior leadership accounts, suggesting prior reconnaissance. Known IoCs: - IP Addresses: - `176.123.4[.]44` - `91.208.197[.]87` - `185.241.208[.]243` (ScreenConnect infrastructure)
INCIDENT DETAILS -
TYPE
Cloud Data Theft
MOTIVATION
Data Theft
IMPACT
Data Compromised: Sensitive files (VPN configurations, remote access procedures), database credentials, secrets, storage account access settings, SQL databases, Azure VM backdoor accountsMicrosoft 365Azure (Key Vaults, Storage Accounts, SQL Databases, Virtual Machines)OneDriveSharePointOperational Impact: Unauthorized access to cloud environments, data exfiltration, forensic artifact removalIdentity Theft Risk: High (privileged account compromise)
DATA BREACH
VPN configurationsRemote access proceduresDatabase credentialsSecretsStorage account access settingsSQL database dataSensitivity Of Data: HighData Exfiltration: Yes
APRIL 2026
492Before Incident
MARCH 2026
504Before Incident
Cyber Attack
04 Mar 2026MEC
Microsoft and Google: Microsoft Warns of Advanced Phishing Campaign Abusing OAuth in Entra ID

Sophisticated Phishing Campaigns Abusing OAuth 2.0 Redirects

483After Incident
CRITICAL-21
MICGOO1772628247
Microsoft Uncovers Sophisticated Phishing Campaigns Abusing OAuth 2.0 Redirects Microsoft has identified a series of phishing attacks targeting government and public-sector organizations by exploiting OAuth 2.0’s redirection features in Microsoft Entra ID and Google Workspace. Unlike traditional credential theft, these campaigns bypass email filters by weaponizing trusted authentication protocols to deliver malware. ### Attack Mechanics Threat actors register malicious apps in their tenant, configuring redirect URIs to point to phishing or malware-hosting domains. Phishing emails disguised as e-signature requests, Teams invites, or password resets lure victims into clicking links that trigger a silent OAuth flow. By manipulating parameters like `prompt=none` and `scope=invalid`, attackers force error redirects without user interaction, masking malicious URLs from scanners. The `state` parameter encodes the victim’s email in Base64, hex, or custom schemes, auto-populating phishing pages for realism. Once clicked, victims are redirected to tools like EvilProxy for session hijacking or prompted to download a ZIP file containing a malicious LNK file. This executes PowerShell for host reconnaissance, then sideloads `crashhandler.dll` via a legitimate `steam_monitor.exe` process to establish command-and-control (C2) communication. ### Detection & Indicators The attack does not exploit vulnerabilities but abuses OAuth 2.0 protocol behavior as outlined in RFC 6749/9700. Key indicators include: - URL Parameters: `prompt=none`, `scope=invalid` (triggers silent redirects) - File Artifacts: `steam_monitor.exe`, `crashhandler.dll`, `crashlog.dat` (DLL sideloading) - Defender Signatures: `Trojan:Win32/Malgent`, `Trojan:Win32/Znyonm`, `Trojan:Win32/WinLNK` - Error Codes: `65001`, `error=interaction_required` (failed SSO, successful redirect) ### Mitigation Strategies Microsoft recommends OAuth governance over patching, including: - App Audits: Regularly review overprivileged OAuth applications. - Access Controls: Enforce Conditional Access and identity protection. - Telemetry & Hunting: Use XDR for cross-signal correlation, flagging anomalies like PowerShell execution from LNK files or DLL sideloading. The campaign underscores the growing trend of protocol abuse in phishing, where attackers leverage legitimate features to evade detection.
INCIDENT DETAILS -
TYPE
Phishing
IMPACT
Microsoft Entra IDGoogle WorkspaceIdentity Theft Risk: High (session hijacking via EvilProxy)
DATA BREACH
LNKDLLZIPPersonally Identifiable Information: Email addresses (encoded in `state` parameter)
FEBRUARY 2026
503Before Incident
JANUARY 2026
640Before Incident
Breach
09 Jan 2026MEC
Panera Bread, Edmunds and CarMax: ShinyHunters claims Panera Bread in alleged data theft

ShinyHunters Claims Data Breaches at Panera Bread, CarMax, Edmunds, and More

495After Incident
CRITICAL-145
PANEDMCAR1769547392
ShinyHunters Claims Data Breaches at Panera Bread, CarMax, Edmunds, and More The extortion group ShinyHunters has alleged large-scale data theft from multiple organizations, including Panera Bread, CarMax, and Edmunds, as part of a broader campaign targeting corporate credentials. According to claims reviewed by The Register and shared on the dark web, the group exfiltrated over 14 million records from Panera Bread including names, email addresses, phone numbers, and account details totaling 760 MB of compressed data. CarMax and Edmunds were also reportedly breached, with 500,000+ records (1.7 GB) and "millions" of records (12 GB), respectively, containing similar personally identifiable information (PII). ShinyHunters stated it accessed Panera’s systems via a Microsoft Entra single-sign-on (SSO) code, while the CarMax and Edmunds breaches stemmed from earlier, unrelated intrusions. The group’s claims align with previous activity by Scattered Lapsus$ Hunters, a linked threat actor that posted CarMax data on a now-defunct leak site last fall, citing compromises in Salesforce environments. The campaign extends beyond these three companies. Last week, ShinyHunters added Crunchbase, SoundCloud, and Betterment to its list of victims, claiming over 50 million records stolen in total. Access to Crunchbase and Betterment was reportedly gained through voice-phishing attacks targeting Okta SSO credentials, a tactic Okta warned about in recent advisories. Betterment confirmed an unauthorized intrusion on January 9, where attackers used social engineering to access third-party marketing platforms and send fraudulent crypto-related messages to customers. Security researchers have observed the group’s expanding operations. Silent Push reported that ShinyHunters’ latest credential-stealing campaign targeted around 100 organizations in the past 30 days, though it remains unconfirmed how many attacks succeeded. Meanwhile, Mandiant is tracking a "new, ongoing ShinyHunters-branded campaign" leveraging voice-phishing to harvest SSO credentials. None of the named companies Panera Bread, CarMax, Edmunds, Crunchbase, or Betterment have publicly responded to the claims. Microsoft and Google stated they had no indication their products were directly affected by the phishing campaign. The incidents underscore the growing threat of social engineering attacks bypassing multi-factor authentication (MFA) to compromise corporate systems.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion, Data Theft for Sale on Dark Web
IMPACT
Data Compromised: Personally Identifiable Information (PII), Account Details, Customer RecordsMicrosoft Entra SSOOkta SSOSalesforce EnvironmentsThird-Party Marketing PlatformsOperational Impact: Unauthorized Access to Corporate Systems, Fraudulent Customer CommunicationsBrand Reputation Impact: Potential Damage Due to Data Exposure and Fraudulent ActivitiesIdentity Theft Risk: High (Exposure of Names, Email Addresses, Phone Numbers, Account Details)
DATA BREACH
NamesEmail AddressesPhone NumbersAccount Details14 million (Panera Bread)500,000+ (CarMax)Millions (Edmunds)50+ million (Total Across All Victims)Sensitivity Of Data: High (PII, Account Credentials)
DECEMBER 2025
639Before Incident
NOVEMBER 2025
637Before Incident
OCTOBER 2025
635Before Incident
SEPTEMBER 2025
633Before Incident
AUGUST 2025
630Before Incident
JULY 2025
628Before Incident
MARCH 2024
749Before Incident
Breach
30 Mar 2024MEC
Panera Bread

Panera Bread Data Breach (2024)

583After Incident
CRITICAL-166
PAN3962339111225
Panera Bread suffered a major data breach exposing sensitive customer information, including Social Security numbers, addresses, birth dates, and passcodes, from 73 million accounts (current and former customers). The breach occurred in two phases: March 30, 2024, and July 12, 2024, with hackers downloading data from a third-party cloud platform and leaking it on the dark web. The incident led to consolidated state and federal lawsuits, alleging negligence in cybersecurity measures. Customers faced risks of identity theft, fraud, and financial losses, with compensation claims categorized into tiers: up to $500 for ordinary losses (e.g., credit monitoring), $2,500 for time spent resolving issues, and $6,500 for documented extraordinary losses. The breach severely damaged customer trust and exposed the company to legal and reputational consequences.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Likely financial (data sold on dark web)
IMPACT
AddressesSocial Security numbersBirth datesPasscodesCustomer account detailsCustomer databaseThird-party cloud platformCustomer Complaints: Multiple (led to class action lawsuit)Brand Reputation Impact: Significant (lawsuits, settlement, public disclosure)Class action lawsuitConsolidated state and federal lawsuitsSettlement payments (up to $6,500 per claimant)Identity Theft Risk: High (SSNs, birth dates, and passcodes exposed)
DATA BREACH
Personally Identifiable Information (PII)Sensitive authentication dataNumber Of Records Exposed: 73,000,000Sensitivity Of Data: High (SSNs, birth dates, passcodes)Data Exfiltration: Confirmed (data found on dark web)NamesAddressesSocial Security numbersBirth datesPasscodes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MEC ?
?
What was MEC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MEC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MEC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MEC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MEC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MEC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MEC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MEC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was MEC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was MEC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was MEC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on MEC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MEC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MEC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?