Cybersecurity Firm BePrime Breached After Skipping Multifactor Authentication

When a security provider lacks basic protections, clients inherit risk they cannot see or control

Illustration: Cybersecurity Firm BePrime Breached After Skipping Multifactor Authentication
AI-generated illustration · Sylvaris

Admin Accounts Without Protection

BePrime, a Mexico-based cybersecurity services provider, was breached after attackers accessed administrator accounts that lacked multifactor authentication. The company provides connectivity and security services to major corporations including Spanish energy provider Iberdrola, steelmaker ArcelorMittal, and Alsea, which operates Starbucks and Domino's locations across Latin America.

On April 20, a threat actor published 12.6 gigabytes of stolen data on a cybercrime forum. The leak included plaintext credentials, client penetration testing reports, and Cisco Meraki API keys that controlled 1,858 network devices and more than 2,600 connected endpoints. The attacker also gained access to live surveillance camera feeds inside client offices.

Supply Chain Risk Made Visible

The breach exposes a structural problem: organizations can implement strong security controls internally but remain vulnerable if their managed service providers do not follow the same standards. BePrime's clients paid for protection but became exposed because the vendor handling their infrastructure lacked a basic safeguard.

Security researcher Alberto Daniel Hill noted the irony that a firm selling cybersecurity was breached for not having two-factor authentication, calling it a total loss of trust. The exposed data included security audit reports that documented client vulnerabilities, essentially providing attackers with a roadmap for future intrusions.

Company Response Draws Criticism

BePrime confirmed the breach in a statement but provided limited details. The company said it activated containment and remediation protocols and asserted there was no impact on client operational continuity. It also announced plans to pursue legal action against journalists and media outlets that reported the incident.

The threat to sue reporters covering a cybersecurity failure drew immediate backlash. Industry observers noted that transparency after a breach is standard practice, and attempts to suppress coverage typically amplify reputational damage rather than contain it.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.