Suspicious activity

MFA virtual device was deactivated from Tor IP address

Risk Level

Imminent Compromised (2)



Orca detected that an API call to 'DeactivateMFADevice' was made from a tor IP address - {MaliciousIp.MaliciousIp}, the operation was successful. This action may indicate of a presence of an unauthorized actor in the cloud environment, since deactivating a virtual MFA device for specific user, may help to impersonate the user more easily and abuse its permissions.
  • Recommended Mitigation

    It is recommended to review the permissions which were used to make this api call. In addition, review the actions of the affected user and enable the virtual MFA device if it is possible.