Suspicious activity

MFA virtual device was deactivated from Tor IP address



Orca detected that an API call to 'DeactivateMFADevice' was made from a tor IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, since deactivating a virtual MFA device for specific user, may help to impersonate the user more easily and abuse its permissions.