
It appears that the well-known cloud services company, PCM, has fallen victim to hacking by a hacker group that managed to gain access to its internal infrastructure.
Headquartered in California and with more than $2 billion in revenue in 2018, PCM is one of the leading cloud and hardware. According to a report by security journalist Brian Krebs, the company discovered the breach in mid-May. Sources told him that the attackers stole credentials for Office 365 and that they were primarily interested in using the stolen data to carry out gift card fraud.
The process followed in this case is no different from other attacks on large IT providers that have occurred in the past, where the hacking group sends phishing to companies and other organizations that deal with gift cards.
Once the group managed to infect a system, it used a customized version of a malware called Mimikatz, which collects usernames and passwords from memory.
Krebs believes this group began operating in 2016, initially focusing on retailers, while its expansion to companies like PCM only began this year.
According to the research, malicious actors could try to target a third-party provider to compromise multiple organizations.

PCM confirmed to Naked Security that the attack affected some customers, but that no personal consumer data was lost
Whether you are a cloud service provider, a hosting company, a small business, or even just a home user with a laptop, preventing breaches is always better than dealing with them.
There are many scammers out there who know how to do their job well, and we must always be prepared to stay safe.
