By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Wherever There’s Ransomware, There’s Service Account Compromise. Are You Protected?
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Wherever There’s Ransomware, There’s Service Account Compromise. Are You Protected?
Tech News

Wherever There’s Ransomware, There’s Service Account Compromise. Are You Protected?

By Viral Trending Content 8 Min Read
Share
SHARE

Until just a couple of years ago, only a handful of IAM pros knew what service accounts are. In the last years, these silent Non-Human-Identities (NHI) accounts have become one of the most targeted and compromised attack surfaces. Assessments report that compromised service accounts play a key role in lateral movement in over 70% of ransomware attacks. However, there’s an alarming disproportion between service accounts’ compromise exposure and potential impact, and the available security measures to mitigate this risk.

Contents
Active Directory Service accounts 101: Non-human identities used for M2MWhy do attackers go after service accounts?High access privilegesLow visibilityLack of security controlsReality bytes: Every company is a potential victim regardless of vertical and sizeSilverfort’s Solution: Unified Identity Security PlatformSilverfort’s service account protection: Automated discovery, profiling, and protection Automated discoveryBehavioral analysis Virtual fencing Conclusion: This is the time to act. Ensure your service accounts are protected

In this article, we explore what makes service accounts such a lucrative target, why they are beyond the scope of most security control, and how the new approach of unified identity security can prevent service accounts from compromise and abuse.

Active Directory Service accounts 101: Non-human identities used for M2M

In an Active Directory (AD) environment, service accounts are user accounts that are not associated with human beings but are used for machine-to-machine communication. They’re created by admins either to automate repetitive tasks, or during the process of installing on-prem software. For example, if you have an EDR in your environment, there’s a service account that is responsible for fetching updates to the EDR agent on your endpoint and servers. Apart from being an NHI, service accounts are not different than any other user account in AD.

Why do attackers go after service accounts?

Ransomware actors rely on compromised AD accounts – preferably privileged ones – for lateral movement. A ransomware actor would conduct such lateral movement until obtaining a foothold that’s strong enough to encrypt multiple machines in a single click. Typically, they would achieve that by accessing a Domain Controller or another server that’s used for software distribution and abusing the network share to execute the ransomware payload on as many machines as possible.

While any user account would suit this purpose, service accounts are best fitted due to the following reasons:

High access privileges

Most service accounts are created to access other machines. That inevitably implies that they have the required access privileges to log-in and execute code on these machines. This is exactly what threat actors are after, as compromising these accounts would render them the ability to access and execute their malicious payload.

Low visibility

Some service accounts, especially those that are associated with an installed on-prem software, are known to the IT and IAM staff. However, many are created ad-hoc by IT and identity personnel with no documentation. This makes the task of maintaining a monitored inventory of service accounts close to impossible. This plays well in attackers’ hands as compromising and abusing an unmonitored account has a far greater chance of going undetected by the attack’s victim.

Lack of security controls

The common security measures that are used for the prevention of account compromise are MFA and PAM. MFA can’t be applied to service accounts because they are not human and don’t own a phone, hardware token, or any other additional factor that can be used to verify their identity beyond their username and passwords. PAM solutions also struggle with the protection of service accounts. Password rotation, which is the main security control PAM solutions use, can’t be applied to service accounts due to the concern of failing their authentication and breaking the critical processes they manage. This leaves service accounts practically unprotected.

Want to learn more about protecting your service accounts? Explore our eBook, Overcoming the Security Blind Spots of Service Accounts, for further insights into the challenges of protecting service accounts and get guidance on how to combat these issues.

Reality bytes: Every company is a potential victim regardless of vertical and size

It was once said that ransomware is the great democratizer that doesn’t discriminate between victims based on any characteristic. This is truer than ever in regard to service accounts. In the past years, we’ve investigated incidents in companies from 200 to 200K employees in finance, manufacturing, retail, telecom, and many others. In 8 out of 10 cases, their attempted lateral movement entailed the compromise of service accounts.

As always, the attackers teach us best where our weakest links are.

Silverfort’s Solution: Unified Identity Security Platform

The emerging security category of identity security introduces a possibility to turn the tables on the free reign adversaries have enjoyed so far on service accounts. Silverfort’s identity security platform is built on a proprietary technology that enables it to have continuous visibility, risk analysis, and active enforcement on any AD authentication, including, of course, the ones made by service accounts.

Let’s see how this is used to thwart attackers from using them for malicious access.

Silverfort’s service account protection: Automated discovery, profiling, and protection

Silverfort enables identity and security teams to keep their service accounts secure in the following manner:

Automated discovery

Silverfort sees and analyzes every AD authentication. This makes it easy for its AI engine to identify the accounts that feature the deterministic and predictable behavior that characterizes service accounts. After a short learning period, Silverfort provides its users with a full inventory of their service accounts, including their privilege levels, sources and destinations, and other data that maps the behavior of each.

Behavioral analysis

For every identified service account, Silverfort defines a behavioral baseline that includes the sources and destinations it normally uses. Silverfort’s engine continuously learns and enriches this baseline to capture the account’s behavior as accurately as possible.

Virtual fencing

Based on the behavioral baseline, Silverfort automatically creates a policy for each service account that triggers a protective action upon any deviation of the account from its standard behavior. This action can be mere alerting or even a full access block. In that manner, even if the service account’s credentials are compromised, the adversary won’t be able to use them to access any resource beyond the ones included in the baseline. All Silverfort’s user is required to do is enable the policy with no additional effort.

Conclusion: This is the time to act. Ensure your service accounts are protected

You’d better get a hold of your service accounts before your attackers do. This is the true forefront of today’s threat landscape. Do you have a way to see, monitor, and secure your service accounts from compromise? If the answer is no, it’s only a matter of time before you join the ransomware stats line.

Want to learn more about Silverfort’s service account protection? Visit our website or reach out to one of our experts for a demo.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Le Wand Lick 3-in-1 Review: Three Times the Pleasure

Retinal screening to detect eye disease

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

What are the best cities for digital nomads?

Android XR Smart Glasses Updates and News for November 2025

TAGGED: Active Directory, Cyber Security, Cybersecurity, Identity Security, Internet, network security, Privileged Access Management, Ransomware
Share This Article
Facebook Twitter Copy Link
Previous Article Macquarie unit to pay nearly $80 million to settle SEC charges
Next Article It’s Always A Good Time To Return To Return To Monkey Island
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Indian market expensive but select sectors shine: Vikash Kumar Jain
Business
Pentagon Announces 6 Critical Areas for Research and Development
Politics
Best Meme Coins Live News Today: Latest Degen Alpha & Market Updates (November 11)
Crypto
The Auto Industry’s Lead Recycling Program is Poisoning People
World News
I asked ChatGPT to build a stunning second income in an ISA from UK dividend stocks and it said…
Business
Le Wand Lick 3-in-1 Review: Three Times the Pleasure
Tech News
PTechnology unveils NPRY token as the engine of a global privacy-first communication economy
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Indian market expensive but select sectors shine: Vikash Kumar Jain

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Indian market expensive but select sectors shine: Vikash Kumar Jain
November 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?