HomeAlertsCASE-5033
Back to Alerts

svc-admin logged into prod-db-primary from an unrecognized IP at 03:00

HighOpenNew alert — not yet reviewed by an analyst.User: Detected: 5 hr ago
AI has no recommended action for this alert.
Needs reviewCorrelated across 5 security events

Shared service account svc-admin@acme-corp.com authenticated to prod-db-primary from IP 91.203.44.12 at 03:00 — a location with zero prior access history. The login was preceded by 4 failed 2FA attempts in 90 seconds. At 03:12, an elevated-privilege SELECT query ran against the customers table returning 14,200 rows — the largest single query in 6 months. The IP resolves to a residential VPN exit node in Eastern Europe. Confidence is 78%: 6 services share this credential, so the access could be from a new deployment runner. A forced password reset is the recommended action.

WHY FLAGGED
Login at 03:00 — first off-hours access in 47 days (normal window: 08:00–19:00)
IP 91.203.44.12 has zero prior association with svc-admin — residential VPN exit, Eastern Europe
4 failed 2FA attempts in 90 seconds immediately preceded the successful login
Elevated-privilege SELECT on customers table — 14,200 rows, largest query in 6 months
AI RecommendationsConflicting risk signals detected — top suggested resolution path presented below.
Force password reset + revoke active sessions
Alert Info
Assigned to
Unassigned
Alert ID
CASE-5033
AI Investigation
Correlated across 5 security events
Alerts
5 linked
Detection
Datastore types
PostgreSQL, Okta
Policy
Risk type
Anomalous Access
User
User
svc-admin (shared)
Department
Ask Matters AI
Hi, I'm Matters AI. Ask me about your alerts, cases, or policies.