Colonial Pipeline ransomware
DarkSide ransomware operators got in through a VPN account that was no longer in use and had no multi-factor authentication. Colonial shut down the largest fuel pipeline on the US East Coast for several days and paid a ransom of about $4.4 million.
Flags logins to dormant accounts and remote access without MFA, while the Dark Web agent surfaces leaked credentials before they are used.