ThreatCluster

Hackers Target NTDS.dit File for Active Directory Access

First seen 4 Feb 2026, 17:06 UTC GbhackersCybersecuritynews 27

Article Content

Browse articles
ThreatCluster

Cyber attackers have been observed exfiltrating the NTDS.dit file, which contains encrypted password hashes for all domain accounts within Active Directory environments. This breach allows attackers to gain full control over enterprise authentication systems, affecting organizations reliant on Active Directory for user account management and security. Security experts are warning of the increased frequency of these attacks.