01
Compromised identities
A valid identity can be weaponized.
62%
of breaches involved the human element
Stolen credentials, hijacked sessions and compromised professional accounts allow attackers to use legitimate interfaces and request data at scale.
VESTA response
Decryption remains conditional on the exact user, session, device, object and operation. A valid account is not a decryption right.
France2024
France Travail
Compromised adviser accounts were used in an intrusion potentially affecting the data of 43 million people.
CNIL source
International2024
Change Healthcare
Stolen credentials opened a remote Citrix portal without MFA, followed by lateral movement, exfiltration and ransomware.
Incident source
Benchmark: Verizon 2026 Data Breach Investigations Report.
02
Concentrated trust
One trusted intermediary can expose millions.
48%
of breaches involved a third party
Providers, support platforms, administrators and reusable service identities can concentrate access to multiple systems inside one trust domain.
VESTA response
No provider, administrator, token or single HSM domain can control decryption alone.
France2024
Viamedis and Almerys
Compromise of two third-party payment operators exposed data relating to more than 33 million people.
CNIL source
International2023
Cloudflare and Okta
A token and service-account credentials exposed through the Okta compromise were reused to access Cloudflare systems.
Cloudflare source
Benchmark: Verizon 2026 DBIR. Third-party involvement reached 48% of breaches.
03
Storage and recovery
Backups are now primary attack targets.
89%
of ransomware victims had backup repositories targeted
Attackers target production files, archives, snapshots and recovery metadata to steal data and remove the victim's ability to recover independently.
VESTA response
A stolen or restored backup remains protected and never becomes a decryption authority.
France2022
CHSF Hospital
A ransomware attack disrupted hospital operations and led to the exfiltration of files containing personal data.
Government source
International2022
LastPass
Attackers accessed cloud storage used for archived production backups and exfiltrated customer backup data, including encrypted vaults.
LastPass source
Benchmark: Veeam 2025 Ransomware Trends report, based on 1,300 ransomware victims.
04
Integrity and substitution
Trusted-looking content may no longer be authentic.
56%
of ransomware attacks succeeded in encrypting data
Encryption, alteration and substitution can make data unusable or cause a trusted system to release the wrong content under an apparently legitimate identity.
VESTA response
Object integrity and cryptographic coherence are verified before protected content is released.
France2026
ANTS portal
A security incident potentially involving disclosure from personal and professional accounts was detected. Its origin and scope remained under investigation.
Official source
International2020
SolarWinds
Malicious code was inserted into trusted Orion software updates and distributed through the legitimate supply chain.
CISA source
Benchmark: Sophos State of Ransomware 2026.