ORCA experienced a significant security event where a firewall misconfiguration led to an opportunity for bots on the internet to launch a brute force attack against the exposed service in an attempt to gain unauthorized access. Thanks to the Rapid 7 solution and MGT’s 24×7 SOC, the attack was detected and the firewall rule was disabled. The security event logs collected in Rapid 7 IDR allowed ORCA to confirm that none of the login attempts during the brute force attack were successful.