700 times a day, six service account passwords crossed the wire in plaintext.
A management server was authenticating to all 11 domain controllers via cleartext LDAP, transmitting 6 service account passwords unencrypted around 700 times a day.
Six high-privilege service accounts transmitted passwords in plaintext roughly 700 times daily. A single packet capture on the network segment compromises the entire infrastructure stack.
These service accounts have broad access across Active Directory. Captured credentials enable lateral movement, privilege escalation, and persistent access, with no additional exploitation required.