Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » Hackers sell data center login credentials of large multinationals
3 min Security

Hackers sell data center login credentials of large multinationals

Sander AlmekindersFebruary 21, 2023 3:04 pmFebruary 21, 2023
Hackers sell data center login credentials of large multinationals

Cybercriminals put stolen login data from large companies up for sale in late January. The data came from a number of the companies’ Asian data centers.

This was discovered by security specialist Resecurity in an investigation ongoing since September 2021. According to the investigation, several data center providers, cloud service providers and MSPs in Asia have been affected by a sustained cyber attack. The cybercriminals, originating from China and some other Asian countries, set out to steal login credentials and other sensitive data from (large) customers.

Bloomberg writes that the affected data center providers are Shanghai-based GDS Holdings and Singapore-based ST Telemedia Global Datacenters. Companies from which login credentials and data were allegedly stolen include Alibaba, Amazon, Apple, BMW, Goldman Sachs, Huawei, Microsoft and Walmart.

Multi-year attacks

The attacks have a long evolution, Resecurity’s security experts discovered. The first malicious cyber activities were spotted in September 2021. During this first attack, the cybercriminals managed to get their hands on a list of CCTV cameras, followed by login credentials of operational employees of the data centers themselves and employees of customers operating in the data centers. In addition, they got their hands on data about services purchased and equipment deployed. In addition, they showed interest is the availability of a “remote hands service (RHS) that allows customers to remotely manage their servers in the data center and troubleshoot problems before that.

In the second wave of attacks, carried out throughout 2022, the cybercriminals again managed to steal a customer database with more than a thousand records at a Singapore data center company. This attack, however, was detected and eventually repelled.

The third and, for now, final episode of this attack occurred recently. Investigators discovered that the cybercriminals put the stolen login credentials and other data of major customers of the affected data center companies up for sale on the dark web. More specifically, this involves the RAMP platform that is mostly used by Initial Access Brokers (IABs) and ransomware criminals.

Also read: European companies plan to increase IT security budget over next three years

Impact unknown

The researchers say they cannot estimate the impact of this large-scale theft of login credentials and other data. By going public now about these attacks on the aforementioned data center providers, they hope to mitigate any impact, but also to create more awareness of this type of attack. Meanwhile, in addition to the affected companies, several CERTs of the affected countries have also been informed about the attack.

Tags:

data centers / hack / login credentials / multinational companies

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Stay tuned, subscribe!

Nieuwsbrieven*

Related

French AI consortium aims for billions from European data center fund

Huawei unveils full-stack AI data center strategy

Dutch data center reboots following fire a week ago

Fire-stricken Dutch data center suffers delay to its recovery

Editor picks

The call for fundamental software skills is getting louder and louder

The IT sector is grappling with a creeping and potentially disruptive...

Huawei integrates storage and AI into a five-layer infrastructure

The number of processed tokens and agents in production is growing ex...

SAP blocks external AI agents. Salesforce and ServiceNow don’t.

At SAP, everything runs through Joule, whether you like it or not

The Netherlands blocks Kyndryl’s acquisition of Solvinity

State Secretary Willemijn Aerdts of Economic Affairs and Climate Poli...

Techzine.tv

What sets Vultr apart from the hyperscalers and neoclouds?

What sets Vultr apart from the hyperscalers and neoclouds?

SAP executive addresses API policy and openness concerns

SAP executive addresses API policy and openness concerns

NetApp balances sovereignty with AI infrastructure needs

NetApp balances sovereignty with AI infrastructure needs

Why major tech companies forked Redis to create Valkey

Why major tech companies forked Redis to create Valkey

Read more on Security

Microsoft lets Defender automatically isolate infected PCs

Microsoft lets Defender automatically isolate infected PCs

Microsoft is expanding its Defender for Endpoint security platform with a feature that can automatically disc...

Mels Dees 3 days ago
No Mythos, no problem: commodity AI can squash bugs too
Top story

No Mythos, no problem: commodity AI can squash bugs too

The latest and greatest AI models from Anthropic and OpenAI are apparently too dangerous to unleash upon the ...

Erik van Klinken May 21, 2026
IBM and Red Hat invest $5 billion in the future of open source

IBM and Red Hat invest $5 billion in the future of open source

IBM and Red Hat announce Project Lightwell: a $5 billion investment to secure open source software with AI. ...

Berry Zwets 3 days ago
Why open source faces its biggest security threat in 2026
Top story

Why open source faces its biggest security threat in 2026

The CTO of the Open Source Security Foundation has a clear message: a major AI-driven cyberattack on open sou...

Coen van Eenbergen 2 days ago

Expert Talks

Power critical workloads with all-NVMe active-active storage for non-stop enterprise operations 

Power critical workloads with all-NVMe active-active storage for non-stop enterprise operations 

Enterprise infrastructure has reached a turning point where planned d...

Five tips for embracing continuous deployment as a DevOps mindset

Five tips for embracing continuous deployment as a DevOps mindset

Continuous deployment offers quicker releases and better software, bu...

The only thing constant in technology is change, except for unrealistic hopefulness

If anyone was ever forced to pick the tritest phrase in the world, it...

mnemonic opens Dutch Security Operations Centre (SOC) and relocates to new office in Utrecht

The new SOC in the Netherlands further strengthens mnemonic’s regio...

Tech calendar

Infosecurity Europe

June 2, 2026 London

.NEXT On Tour Amsterdam

June 9, 2026 Amsterdam

Oxygenate

June 11, 2026 Hilversum

Google Cloud AI Live

June 11, 2026 Amsterdam

VivaTech

June 17, 2026 Paris Expo Porte de Versailles 1 Place de la Porte de Versailles Pavillon 7 F-75015 Paris France

GITEX AI EUROPE 2026

June 30, 2026 Messe Berlin Exhibition Center, South Entrance

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2026 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement