EC-Council says the hacker had administrative access to its enterprise email which it stores with a cloud service provider that it didnt name he was able to compromise about 2% of the councils customer email accounts before its security team managed to wrest back control. This circumvented the council’s best-practices of using complex passwords and two-factor authentication (2FA) The council says it has changed policies on management of personal information, improved existing data retention policies, introduced 2FA for member portals, improved security procedures and systems.”]

