01Compromised identities
A valid identity can be weaponized.
62%of breaches involved the human element
Stolen credentials, hijacked sessions and compromised professional accounts allow attackers to use legitimate interfaces and request data at scale.
VESTA responseDecryption remains conditional on the exact user, session, device, object and operation. A valid account is not a decryption right.
France2024
France Travail
Compromised adviser accounts were used in an intrusion potentially affecting the data of 43 million people.
CNIL sourceInternational2024
Change Healthcare
Stolen credentials opened a remote Citrix portal without MFA, followed by lateral movement, exfiltration and ransomware.
Incident sourceBenchmark: Verizon 2026 Data Breach Investigations Report.
02Concentrated trust
One trusted intermediary can expose millions.
48%of breaches involved a third party
Providers, support platforms, administrators and reusable service identities can concentrate access to multiple systems inside one trust domain.
VESTA responseNo provider, administrator, token or single HSM domain can control decryption alone.
France2024
Viamedis and Almerys
Compromise of two third-party payment operators exposed data relating to more than 33 million people.
CNIL sourceInternational2023
Cloudflare and Okta
A token and service-account credentials exposed through the Okta compromise were reused to access Cloudflare systems.
Cloudflare sourceBenchmark: Verizon 2026 DBIR. Third-party involvement reached 48% of breaches.
03Storage and recovery
Backups are now primary attack targets.
89%of ransomware victims had backup repositories targeted
Attackers target production files, archives, snapshots and recovery metadata to steal data and remove the victim's ability to recover independently.
VESTA responseA stolen or restored backup remains protected and never becomes a decryption authority.
France2022
CHSF Hospital
A ransomware attack disrupted hospital operations and led to the exfiltration of files containing personal data.
Government sourceInternational2022
LastPass
Attackers accessed cloud storage used for archived production backups and exfiltrated customer backup data, including encrypted vaults.
LastPass sourceBenchmark: Veeam 2025 Ransomware Trends report, based on 1,300 ransomware victims.
04Integrity and substitution
Trusted-looking content may no longer be authentic.
56%of ransomware attacks succeeded in encrypting data
Encryption, alteration and substitution can make data unusable or cause a trusted system to release the wrong content under an apparently legitimate identity.
VESTA responseObject integrity and cryptographic coherence are verified before protected content is released.
France2026
ANTS portal
A security incident potentially involving disclosure from personal and professional accounts was detected. Its origin and scope remained under investigation.
Official sourceInternational2020
SolarWinds
Malicious code was inserted into trusted Orion software updates and distributed through the legitimate supply chain.
CISA sourceBenchmark: Sophos State of Ransomware 2026.