Full Report
A data breach involving radialentertainment.com was reported in May 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Radial Entertainment Email Compromise and PII Exposure
## Executive Summary
Radial Entertainment experienced a targeted security breach involving unauthorized access to specific employee email accounts by an external third party. The incident, which persisted for nearly three months, resulted in the exposure of sensitive Personal Identifiable Information (PII) for 182 individuals. The breach was contained following discovery, though the high sensitivity of the stolen data (Social Security numbers) presents a lasting risk of identity theft.
## Incident Details
- **Discovery Date:** April 16, 2026
- **Incident Date:** November 25, 2025 – February 18, 2026
- **Affected Organization:** Radial Entertainment (radialentertainment[.]com)
- **Sector:** Entertainment / Media
- **Geography:** Undisclosed (Global/Digital impact)
## Timeline of Events
### Initial Access
- **Date/Time:** November 25, 2025
- **Vector:** External Hacking / Unauthorized Login
- **Details:** An unidentified third party gained access to specific corporate email accounts.
### Lateral Movement
- **Details:** While the report focuses on email access, the investigation noted that the unauthorized access was maintained across multiple employee accounts over a three-month period, suggesting potential credential harvesting or session hijacking to maintain access.
### Data Exfiltration/Impact
- **Details:** Sensitive data residing within the compromised email threads was accessed. This included the full names and Social Security numbers (SSNs) of 182 individuals.
### Detection & Response
- **Discovery:** April 16, 2026 (Approximately 5 months after initial entry).
- **Response actions taken:** Investigation launched into the scope of the breach; public disclosure and regulatory reporting occurred on May 5, 2026.
## Attack Methodology
- **Initial Access:** External hacking; unauthorized access to employee email accounts.
- **Persistence:** Sustained access to mailboxes from Nov 2025 to Feb 2026.
- **Privilege Escalation:** Not specified, but involved access to sensitive PII stored in administrative or HR-related email communications.
- **Defense Evasion:** The attackers remained undetected for approximately 142 days.
- **Credential Access:** Likely achieved through credential stuffing, phishing, or exploitation of weak authentication protocols.
- **Discovery:** Reconnaissance of email contents to identify high-value PII (SSNs).
- **Lateral Movement:** Accessing multiple disparate employee mailboxes.
- **Collection:** Gathering sensitive documents and data from email attachments and body text.
- **Exfiltration:** Unauthorized viewing/theft of PII.
- **Impact:** Medium severity; high risk of identity theft and potential Business Email Compromise (BEC).
## Impact Assessment
- **Financial:** Potential costs related to credit monitoring services for victims and legal/regulatory fines.
- **Data Breach:** Exposure of Names and SSNs for 182 individuals.
- **Operational:** Diversion of resources for forensic investigation and incident response.
- **Reputational:** Public disclosure of security weaknesses regarding employee communication handling.
## Indicators of Compromise
- **Network indicators:** Unauthorized login attempts from anomalous IP addresses (Specific IPs not disclosed).
- **File indicators:** Not applicable (Cloud/Email breach).
- **Behavioral indicators:** Unusual mailbox access patterns and logins outside of standard geographic locations or business hours.
## Response Actions
- **Containment measures:** Secured compromised email accounts and terminated unauthorized sessions.
- **Eradication steps:** Audited mailbox permissions and access logs.
- **Recovery actions:** Notified affected individuals and reported the breach to relevant authorities on May 5, 2026.
## Lessons Learned
- **Key takeaways:** The long dwell time (Nov to April) highlights a significant gap in proactive monitoring and alerting for anomalous email logins.
- **What could have been done better:** Earlier detection through automated "impossible travel" alerts or MFA challenge failures could have mitigated the duration of the exposure.
## Recommendations
- **Implement Phishing-Resistant MFA:** Deploy hardware keys (e.g., FIDO2) or authenticator apps to replace SMS or password-only logins.
- **Email Security Hardening:** Deploy advanced threat protection (ATP) for email to detect anomalous behavior and unauthorized access.
- **Data Retention Policy:** Enforce policies to move sensitive PII (like SSNs) out of email environments and into encrypted, access-controlled databases.
- **Monitoring:** Implement regular audits of mailbox access logs and third-party application permissions.