This session will share a case study of a real incident we faced in incident response. We’ll jump straight into the key investigative developments and plot twists, sharing insights into attacker TTPs, investigative methodology, and key takeaways for protecting complex multi-cloud environments. Join us to learn how attackers circumvented advanced security controls to rob over $100M by compromising environment in AWS, Azure, and GitHub. Leveraging a clever combination of targeted social engineering and sophisticated cloud-native tradecraft, attackers were able to stay one step ahead of the victim for months while monetizing their access and evading detection. We’ll share every step of the attack and our unique investigation, accompanied with forensic evidence and visuals which reveal the attack flow and our evolving investigative understating, until the final unravelling of the attack.