Software company Citrix was attacked by hackers last year. Now, the company has confirmed that the attackers gained access to its internal network through a not-so-specialized technique. That technique was called password spraying. Password spraying is a type of attack in which hackers try to gain access to a large number of accounts using common passwords.
Hackers managed to steal many Citrix files. According to the investigation, the attackers had access to the company's systems from October 2018 to March 2019. The attack on Citrix taught a lesson to all organizations . No company can be completely secure, which is why many protection measures should be taken. Creating strong and unpredictable passwords is one of the most important things that organizations should be concerned about. In addition, access procedures (two-factor authentication, etc.) are also very important.
The common thread in all the major breaches that have occurred in recent years is that the attackers move slowly. That is, it is common for them to start the attack on something of little value and move through the network until they reach something of value. In the case of Citrix, the hackers had managed to remain unnoticed for a very long time . They used the technique of password spraying and slowly stole the company's files

Florida -based Citrix, which provides services to more than 400,000 companies, is still investigating the number and type of files that were compromised.
After the Citrix incident, organizations began to realize that data breaches are one of the biggest threats, even for large companies with various systems and protection programs in place. A “zero trust” mindset needs to be adopted . There should always be control, never trust. If a hacker manages to gain access to the system, organizations should be able to prevent hackers from penetrating the system further . This mindset shifts the conversation from detection and prevention to containment and remediation.
