March 24, 2026
Peer-organized operation disrupts BLUECRAB operations
Denison Security
Denison ITS, in cooperation with a number of peer institutions, identified at least ten breached accounts across these institutions which were being used to maintain persistence in computing environments, especially in email tenants and file sharing applications.
Disrupting these applications was an important step in disrupting BLUECRAB’s operations. In short, we disrupted their data source by removing their access to accounts they should not have had access to. These accounts were generally not used to send phishing or spear phishing attack messages. Instead, these were used to host forms and data sheets on potential victims.