Skip to content
Techzine Europe
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Europe
  • Techzine Netherlands
Techzine News Security Hackers sell data center login credentials of large multinationals
3 min Security

Hackers sell data center login credentials of large multinationals

Sander AlmekindersFeb 21, 2023, 2:04 PM UTCFebruary 21, 2023
Hackers sell data center login credentials of large multinationals

Cybercriminals put stolen login data from large companies up for sale in late January. The data came from a number of the companies’ Asian data centers.

This was discovered by security specialist Resecurity in an investigation ongoing since September 2021. According to the investigation, several data center providers, cloud service providers and MSPs in Asia have been affected by a sustained cyber attack. The cybercriminals, originating from China and some other Asian countries, set out to steal login credentials and other sensitive data from (large) customers.

Bloomberg writes that the affected data center providers are Shanghai-based GDS Holdings and Singapore-based ST Telemedia Global Datacenters. Companies from which login credentials and data were allegedly stolen include Alibaba, Amazon, Apple, BMW, Goldman Sachs, Huawei, Microsoft and Walmart.

Multi-year attacks

The attacks have a long evolution, Resecurity’s security experts discovered. The first malicious cyber activities were spotted in September 2021. During this first attack, the cybercriminals managed to get their hands on a list of CCTV cameras, followed by login credentials of operational employees of the data centers themselves and employees of customers operating in the data centers. In addition, they got their hands on data about services purchased and equipment deployed. In addition, they showed interest is the availability of a “remote hands service (RHS) that allows customers to remotely manage their servers in the data center and troubleshoot problems before that.

In the second wave of attacks, carried out throughout 2022, the cybercriminals again managed to steal a customer database with more than a thousand records at a Singapore data center company. This attack, however, was detected and eventually repelled.

The third and, for now, final episode of this attack occurred recently. Investigators discovered that the cybercriminals put the stolen login credentials and other data of major customers of the affected data center companies up for sale on the dark web. More specifically, this involves the RAMP platform that is mostly used by Initial Access Brokers (IABs) and ransomware criminals.

Also read: European companies plan to increase IT security budget over next three years

Impact unknown

The researchers say they cannot estimate the impact of this large-scale theft of login credentials and other data. By going public now about these attacks on the aforementioned data center providers, they hope to mitigate any impact, but also to create more awareness of this type of attack. Meanwhile, in addition to the affected companies, several CERTs of the affected countries have also been informed about the attack.

Tags:

data centers / hack / login credentials / multinational companies

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

EU aims to save water supply as data centers dry up

Belgium will need two nuclear reactors to power data centers in 2035

OpenAI commits to mega data center in UAE as part of global expansion

Qualcomm develops custom data center CPUs with Nvidia technology

Editor picks

Microsoft launches free European Security Program: what does it entail?

Microsoft President Brad Smith is living up to his political-sounding...

Snowflake makes building AI apps and agents easier

Snowflake is launching a series of new features that make it easier f...

Only European partners can access lowest VMware tier – for now

Broadcom continues to shake up VMware

Snowflake Openflow extracts data from any enterprise system

A new tool for data engineers has just been unveiled at the Snowflake...

Insight: IT in Healthcare

Children with autism treated months earlier thanks to process automation

In the United States, one in 31 children is diagnosed with autism. Th...

EU launches action plan for cybersecurity in healthcare

The European Commission proposes an EU-wide action plan to protect th...

Orange Cyberdefense turns security into a business enabler

Orange Cyberdefense turns security into a business enabler

CEO approaches security from a left and right side

EU proposal gives medical data to product developers

EU proposal gives medical data to product developers

Several organizations want the EU to reshape the European Health Data...

Read more on Security

authID makes passwords obsolete with Ping Identity

authID makes passwords obsolete with Ping Identity

authID has announced a new integration with Ping Identity. Through PingOne DaVinci, organizations can easily ...

Erik van Klinken 14 hours ago
Hacking group steals Salesforce data by impersonating IT support

Hacking group steals Salesforce data by impersonating IT support

A new report from Google Threat Intelligence Group (GTIG) reveals a threat to Salesforce instances. However, ...

Erik van Klinken 19 hours ago
Data Lifecycle Management: The Overlooked Step of Secure Deletion
Expert Talks

Data Lifecycle Management: The Overlooked Step of Secure Deletion

In 2025, data is everywhere. Flowing through apps, cloud platforms, devices across the globe and every organi...

Guest Author 1 day ago
Microsoft launches free European Security Program: what does it entail?
Top story

Microsoft launches free European Security Program: what does it entail?

Microsoft President Brad Smith is living up to his political-sounding job title. After a series of appearance...

Erik van Klinken 15 hours ago

Whitepapers

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Try the latest high-end Synology backup system for free

Try the latest high-end Synology backup system for free

How do you ensure that your data is secure and can be quickly restore...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Tech calendar

Viva Technology

June 11, 2025 1 place de la porte de Versailles,75015,Paris,France

Kaseya DattoCon Europe

June 17, 2025 Dublin

Nutanix Cloud Day Nederland 2025

June 17, 2025 Zeist

Akamai Customer Day Benelux

June 18, 2025 Nieuwegein

Nürnberg Digital Festival 2025

June 30, 2025 Nürnberg

GITEX DIGI_HEALTH 5.0 - Thailand

September 10, 2025 BITEC Bangkok, Thailand

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement

Notifications