An Attacker Already Inside. Three Environments Down.

In late October 2025, a SaaS platform company serving enterprise clients across multiple industries discovered something no business ever wants to find: a threat actor was already inside their systems, had been for some time, and was now making active demands backed by threats of further compromise.

The decision was made to pull everything offline. Production, UAT, and Staging all went down as an emergency containment measure. Enterprise clients had to be notified. For a SaaS company, that kind of outage is not just a technical problem.

This was not opportunistic. Evidence pointed to a deliberate, targeted campaign. The attacker had done their homework, found a way past MFA controls through the client's VDI environment, and had access that spanned multiple environments. Every hour without answers gave them more time to go deeper.

QuasarCyberTech was formally engaged on 30 December 2025. The team mobilized the same day. The central question leadership needed answered was simple to ask but hard to answer: should they shut down their cloud instances entirely, and if so, how do you do that without losing the forensic evidence you need?

Every Decision Had Irreversible Consequences

The attacker was still active. Any hasty move, whether bringing an environment back up too soon or making uncoordinated changes to infrastructure, risked two things at once: tipping off the attacker and destroying the forensic trail before root cause could be established. The team had to move carefully without moving slowly.

The business pressure was real. Enterprise clients were in a holding pattern. Revenue had stopped. Leadership team wanted a date. Our position stayed consistent throughout: not until we validate the entry vector and confirm the platform is clean. That recommendation was uncomfortable. It was also the right call.

The scope kept growing. What initially looked like a single environment breach turned out to be broader. The same suspicious IP addresses appeared across multiple client environments. This was not an isolated intrusion. There was a systemic exposure that needed to be addressed at the root, not patched over.

"Restoring services without verified security assurance may lead to greater operational and brand impact. We therefore recommend providing controlled access so we can complete our full assessment, validate the entry vector, and ensure that the platform can go live securely and confidently."

That position held throughout. Security over speed, even when speed was what everyone wanted.

Forensics, Containment, and 24x7 Defence

The team was on it the same day. The work ran on multiple tracks at once, and it did not stop for nights or weekends.

1
Day 1, 30 December 2025
Emergency Engagement & Evidence Collection
QCT formally engaged and the team got to work the same day. Six weeks of AWS Gateway logs, VPC logs, S3 access logs, and UI access logs were received and secured. Forensic analysis and containment advisory ran simultaneously from the first hours.
2
Day 1–3
Forensic Log Analysis & IOC Extraction
QCT built custom scripts to process logs faster across AWS Gateway, S3, VPC, WAF, and UI layers. The analysis surfaced 17 suspicious IP addresses for immediate blacklisting, 13 accounts still running on factory-default passwords, and S3 buckets configured with open public read access that had no business being public.
3
Days 1 to 7 (Ongoing)
Attack Vector Investigation
Evidence pointed to an Okta MFA bypass via a compromised VDI session. Once inside, the attacker pulled data from SharePoint and connected repositories. Credentials being shared between staging and production made lateral movement straightforward. This was a deliberate, researched attack, not a scan-and-exploit hit of opportunity.
4
Parallel Track
Application Layer Penetration Testing
While forensics was running, QCT's offensive security team conducted application-layer penetration testing in parallel. What they found made the breach easier to understand: the application had multiple critical vulnerabilities that, standing alone, would have given any attacker full platform control.
5
Post-Containment
Controlled Restoration Roadmap
QCT designed a structured 6-phase restoration plan. Each phase required security validation before the next could begin. The plan was deliberately built to resist the pressure to move fast before things were truly safe.
6
Ongoing
Cloud Security Monitoring & SOC Onboarding
Amazon GuardDuty was switched on and configured. QCT took on interim cloud security monitoring with check-ins every two days, weekends included. As part of the expanded scope, full SOC onboarding was kicked off to move toward continuous 24x7 coverage going forward.

A 6-Phase Controlled Restoration Roadmap

The biggest risk after an incident like this is bringing things back up too fast. Business pressure pushes toward speed; security demands patience. QCT's restoration plan was structured to enforce that patience. Each phase had a defined security gate. Nothing advanced until the previous phase was validated and signed off.

0
Freeze & Preserve EvidenceComplete halt of all environment changes. All logs archived and secured for forensic integrity. No restoration until evidence collection confirmed complete.
1
Controlled Staging RestorationRebuild from a pre-compromise snapshot in isolation. Staging environment brought up in monitored, access-controlled conditions only.
2
Application ValidationComplete penetration testing and secure code review of the application layer. QCT confirmed the entry vector before any environment went live.
3
Infrastructure HardeningIAM enhancement, S3 access controls remediated, network security baselines applied. All default credentials rotated. MFA enforced universally.
4
Limited UAT Bring-Up Under SOC WatchControlled testing under active SOC monitoring. QCT and client teams jointly monitored logs and alerts before expanding access.
5
Production Restoration: Secure-for-Go-LiveFull production restoration only after QCT issued Secure-for-Go-Live confirmation. Post-go-live penetration testing conducted to validate security under real production conditions.

From Active Breach to Continuous Resilience

When the immediate threat was neutralized, the work did not end. The engagement expanded because the client had seen what the QCT team could do under pressure and decided they wanted that on an ongoing basis.

Breach Contained
Active threat actor contained within hours of QCT's engagement. All environments brought offline in a controlled, evidence-preserving sequence.
Root Cause Identified
Full forensic investigation completed across 6+ weeks of AWS and application logs. Attack vector confirmed and documented.
Secure Restoration
6-phase controlled recovery executed. Production came back online only after QCT issued a Secure-for-Go-Live sign-off, specifically to prevent re-compromise.
Continuous Defence
SOC monitoring activated. GuardDuty enabled. QCT providing advisory updates every 48 hours including weekends for the first month post-recovery.

The expanded engagement now covers Incident Response, Digital Forensics, Application VAPT, Secure Code Review, Cloud Security Monitoring, SOC Operations, and Compliance. It started as a call made in a crisis. It became a long-term partnership built on trust earned under real pressure.