Donut417 Left SSH open on an internal GRPS Testing Gateway router… Was supposed to be internal only. But a T-Mobile engineer left it exposed to thee public Internet by mistake. Because this SSH instance was never meant to be public, no one bothered to set up any mitigations against brute force attacks on the system. Cybercriminal managed to successfully brute force in, and from there, had access to all kinds of other internal systems. Pivoted. Network segmentation was also not present.
Big lessons learned.