Northledger has received a ransom demand from a threat actor claiming to have compromised the company’s main public-facing website and accessed sensitive customer and business data.
The attackers have provided a small sample of information as proof, including customer contact details, supplier records, internal documents, and financial data. They are demanding payment in exchange for deleting the stolen information and preventing its release.
Northledger’s website is still online, and the affected systems have not yet been fully isolated. The organisation needs to understand how the attackers gained access, what activity they carried out, and whether they still have access to the environment.
You have been given access to the live Northledger infrastructure to investigate the incident.
Your task is to examine the public-facing website and connected systems, identify the vulnerability or weakness that enabled the compromise, obtain access to the affected environment, and determine how the threat actor reached the exposed data.
