Take One Systems, an IT services provider, discovered that hackers had accessed its internal file server as part of a ransomware attack. That file server held a collection of administrative notes the company kept for a client organization, including a Microsoft 365 admin password, a domain registration admin password, notes on individual users’ Microsoft 365 passwords, PC setup records containing device passwords, and login details for an Intuit QuickBooks Online account. The company has not confirmed whether the files were actually stolen and retained by the attacker or whether they might be made public, but says it is treating the situation seriously and has already taken steps to contain it, including changing the exposed passwords and enabling multi-factor authentication on the affected accounts.
This notice is addressed to staff at the client organization referred to in the letter as Koyu (with the exception of a group called EagleVines). If you received this notification, it likely means your Microsoft 365 login information, or notes referencing a password created for you, were stored on the compromised server.
What information was exposed?
- Microsoft 365 admin account password
- Domain registration admin password
- Microsoft 365 user login passwords, recorded in internal setup notes
- PC setup notes, including passwords created during device configuration
- Intuit QuickBooks Online login credentials
Take One Systems has already changed the passwords it controlled directly (admin, domain, security software, and QuickBooks accounts) and confirmed that multi-factor authentication is active on those accounts. No free credit monitoring or identity protection service is mentioned in this letter.
What should you do now?
- Change your Microsoft 365 password as soon as possible, even if you haven’t been told your specific password was affected — the letter recommends this for everyone at the client organization.
- Turn on multi-factor authentication (MFA) for your Microsoft 365 account, using SMS or an authenticator app, if you haven’t already.
- If you reused your Microsoft 365 password on any other site or account, change it there too, since reused passwords are a common way attackers expand access after a breach.
- Watch for phishing emails that reference this incident or impersonate Take One Systems, your employer, or Microsoft — attackers sometimes use breach notifications as a lure.
- If your device password was among the PC setup notes, note that the letter states this alone poses low risk since physical access to the device would also be required, but it’s still reasonable to change local device passwords when convenient.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, especially since exposed credentials can sometimes be paired with other personal data found in unrelated breaches.
If you have questions, Take One Systems can be reached at [email protected].