Cybersecurity Firm BePrime Breached After Skipping Multifactor Authentication
When a security provider lacks basic protections, clients inherit risk they cannot see or control
Admin Accounts Without Protection
BePrime, a Mexico-based cybersecurity services provider, was breached after attackers accessed administrator accounts that lacked multifactor authentication. The company provides connectivity and security services to major corporations including Spanish energy provider Iberdrola, steelmaker ArcelorMittal, and Alsea, which operates Starbucks and Domino's locations across Latin America.
On April 20, a threat actor published 12.6 gigabytes of stolen data on a cybercrime forum. The leak included plaintext credentials, client penetration testing reports, and Cisco Meraki API keys that controlled 1,858 network devices and more than 2,600 connected endpoints. The attacker also gained access to live surveillance camera feeds inside client offices.
Supply Chain Risk Made Visible
The breach exposes a structural problem: organizations can implement strong security controls internally but remain vulnerable if their managed service providers do not follow the same standards. BePrime's clients paid for protection but became exposed because the vendor handling their infrastructure lacked a basic safeguard.
Security researcher Alberto Daniel Hill noted the irony that a firm selling cybersecurity was breached for not having two-factor authentication, calling it a total loss of trust. The exposed data included security audit reports that documented client vulnerabilities, essentially providing attackers with a roadmap for future intrusions.
Company Response Draws Criticism
BePrime confirmed the breach in a statement but provided limited details. The company said it activated containment and remediation protocols and asserted there was no impact on client operational continuity. It also announced plans to pursue legal action against journalists and media outlets that reported the incident.
The threat to sue reporters covering a cybersecurity failure drew immediate backlash. Industry observers noted that transparency after a breach is standard practice, and attempts to suppress coverage typically amplify reputational damage rather than contain it.
- https://databreaches.net/2026/04/20/breach-at-be-prime-cybersecurity-company-exposes-client-data-and-surveillance-systems-be-prime-threatens-journalists/
- https://www.escudodigital.com/en/cybersecurity/breach-at-cybersecurity-company-exposes-client-data-and-surveillance-systems.html
- https://sharkstriker.com/blog/april-2026-data-breaches/