Principle Security Principle Security.
The Breach That Never Touched the Network
← All articles

August 30, 2026 · 7 min read · By Principle Security

The Breach That Never Touched the Network

This summer we worked a live incident at a credit union where every internal control came back clean. Endpoint detection across hundreds of machines: nothing. The identity provider's logs, thousands of sign-ins reviewed: nothing but a burst of blocked probes from hosting-provider IP space. No malware, no rogue logins, no lateral movement, no data staged for exfiltration.

And yet the institution's domain was serving an attacker's content, a wildcard TLS certificate covering every one of its subdomains had been issued to someone else, and inbound email was pointed at a server the attacker controlled. Members could have been phished at the real URL, with a padlock, and nothing in the security stack would have fired.

The attack lived in the control planes

The entire operation happened in accounts the credit union logs into a few times a year: the DNS hosting account, taken over through a password reset and a well-worked support desk. The domain registrar account, used to repoint the domain's nameservers. Public certificate authorities, which issued valid certificates to whoever could pass a DNS-based check at a moment when the attacker controlled DNS. None of these systems live on the network. None of them run an EDR agent. Most of them are not in anyone's asset inventory.

We call these control planes: third-party administrative surfaces that decide how the world reaches you. The registrar decides which nameservers answer for your domain. The DNS host decides where your website and email actually point. The certificate ecosystem decides who can present a padlock as you. Whoever holds those accounts holds your institution's identity on the internet, and your firewall has no opinion about any of it.

This is the pattern, not an exception

When we analyzed the NCUA's first full year of cyber incident reports, 69% of 1,072 incidents traced back to a third party. The industry conversation about third-party risk tends to focus on core processors and insurers, and this summer's headlines have made that concrete for every credit union leader. But the registrar you pay $20 a year is a third party too, and it sits upstream of everything: your website, your online banking redirect, your email, your password resets.

Part 748 expects vendor management proportionate to risk. Almost every credit union we assess has a due-diligence file on its core processor. We have never once been handed a due-diligence file on a registrar.

What clean internal logs actually told us

The instinct in an incident like this is to hunt the network for the intrusion. That hunt matters, because you need to prove the attacker didn't also get inside, and in our case the clean EDR and identity review did exactly that: it let leadership scope the incident accurately, brief the board accurately, and aim the response where the fight actually was. But the deeper lesson is uncomfortable: a modern attacker can run a complete impersonation of your institution, including mail interception, without ever needing your network at all.

Five moves to make this quarter

1. Inventory your control planes. Registrar, DNS host, certificate issuers, email routing, cloud consoles, CDN accounts. Who holds each account, what MFA protects it, who would even notice a change.

2. Put phishing-resistant MFA on the registrar and DNS host. Hardware keys, not SMS. These accounts deserve the same treatment as domain admin, because that is what they are.

3. Ask your registrar about registry-level locking. The consumer-grade transfer lock is not what you think it is. That one gets its own article.

4. Monitor from the outside. Your nameserver delegation, your MX records, and certificate transparency logs for your domains (more on those). All of it is watchable for free, and a change fires in minutes instead of after a member calls the branch.

5. Put a domain-hijack scenario in your incident response plan and tabletop it. The playbook for "our domain is serving someone else's content" involves abuse desks, registrars, registries and certificate authorities, not your firewall. The first time you learn those escalation paths should not be live.

The perimeter you defend is bigger than the network you administer. The institutions that internalize that before an incident are the ones whose examiners read about it in a well-documented vendor file instead of an incident report.

Transform your business today.