{"vendor":{"name":"Acme Supplies SRL","address":"Rue de la Loi 100, 1040 Brussels, Belgium","contact_email":"security@acme-supplies.be"},"customer":{"name":"Dupont & Fils SAS","account_id":"ACM-CUST-2026-0418"},"incident_id":"SEC-2026-014","severity":"S1","detected_on":"2026-03-14T09:07:00+01:00","resolved_on":"2026-03-14T13:22:00+01:00","duration":"4h 15m","impact_on_customer":"Between 09:07 and 13:22 CET on 14 March 2026, users of Dupont & Fils SAS at the Lille-Lesquin, Lyon and Paris sites were unable to place orders or view deliveries through the Acme Supplier Portal. Queued orders were held and released on recovery; no orders were lost, duplicated, or delivered to the wrong site. Invoicing, inventory and shipment data were not affected. No personal data was accessed or exfiltrated.","root_cause":"A credential-phishing campaign targeted Acme's support-operations staff on 13 March 2026 at 23:41 CET. One support account was compromised and used at 08:54 CET on 14 March to upload a malformed policy file to the Acme Supplier Portal's WAF. The malformed rule caused the WAF to reject ~94% of legitimate POST requests with a 403 response, which cascaded into a customer-visible outage on the portal's ordering APIs. Neither the customer's data nor any downstream ERP was reached. The root cause is therefore a combination of (a) a successful phishing compromise, (b) insufficient four-eyes control on WAF policy changes, and (c) missing automated policy-validation gates in the CI/CD pipeline.","timeline":[{"timestamp":"2026-03-13T23:41:00+01:00","event":"Phishing email received by 14 Acme support staff; one clicks and submits credentials."},{"timestamp":"2026-03-14T08:54:00+01:00","event":"Compromised credentials used to push a malformed WAF policy to production."},{"timestamp":"2026-03-14T09:07:00+01:00","event":"External synthetic probes and customer tickets confirm portal 403 errors; P1 opened."},{"timestamp":"2026-03-14T09:12:00+01:00","event":"Incident commander assigned; customer communication sent to all affected accounts."},{"timestamp":"2026-03-14T09:38:00+01:00","event":"WAF policy reverted to previous version; traffic partially restored."},{"timestamp":"2026-03-14T10:05:00+01:00","event":"Compromised account disabled, session tokens revoked, MFA reset forced for all support staff."},{"timestamp":"2026-03-14T13:22:00+01:00","event":"Full recovery verified across all regions; queued orders released. P1 closed."},{"timestamp":"2026-03-17T10:00:00+01:00","event":"Executive post-mortem with customer sponsors; this report issued."}],"corrective_actions":["WAF policy reverted and validated against a regression suite before re-enablement.","Compromised Acme support account disabled; MFA reset forced for all Acme support and engineering staff.","Session tokens revoked across the portal; forced re-authentication for all active sessions.","Dupont & Fils order queue drained manually against the order ledger to confirm no duplicates or losses."],"preventive_actions":["Introduce a mandatory four-eyes approval on all WAF and network-policy changes in production (blocker merged into the CI/CD pipeline on 2026-03-19).","Add automated policy-validation gates (dry-run against the last 24h of anonymised request traffic) before any WAF rule reaches production.","Run an accelerated phishing-simulation and awareness refresh for all Acme staff by 2026-04-30, with mandatory retake on failure.","Roll out FIDO2 hardware keys to all support and engineering staff by 2026-06-30, retiring TOTP-based MFA for privileged actions."],"service_credits_optional":{"amount":1850.0,"currency":"EUR"},"signatory":{"name":"Marc Verhaeghe","title":"Director, Customer Operations","date":"2026-03-17"}}