CRITICALALT-2026-11853h ago

Privileged Access Anomaly: Service Account Credential Sharing

Shared service account SVCACCT-CORE detected logging in from 3 different geographic locations within 15 minutes. Credential compromise suspected.

Export Report
Compound Score
83/100
Confidence
95/100
FP Likelihood
low
Subject
SVCACCT-CORE
Domains
1/100
Subject
SVCACCT-CORE
service_accountCore Banking Service Account
Domains
security
Assigned To
Raj Patel
Teachers Federal Credit Union

Summary

Member Service Representative MSR-4821 processed 7 wire transfer overrides totaling $340,000 during their direct supervisor's PTO window. Combined with after-hours CRM access and 2 newly created beneficiary accounts, this pattern matches FinCEN Advisory 2025-A003 insider threat indicators.

Evidence Chain (5 items)

#13/28/2026, 2:23:00 PMoverride_transaction

Processed 4 wire transfers >$25K each with manager override bypass

Source: Symitar Core Banking | Ref: WR-78291,78292,78295,78296

Override volume 7x monthly baseline. Transfers to 2 newly created beneficiary accounts.
#23/27/2026, 12:00:00 AMleave_pattern_change

Direct supervisor (Branch Manager K. Johnson) on approved PTO Mar 27-31

Source: UKG HRIS | Ref: PTO-2847

Override clustering correlates with supervisor absence window (r=0.94)
#33/27/2026, 10:14:00 PMafter_hours_access

Accessed 12 member profiles in CRM at 10:14 PM — none tied to open service requests

Source: Salesforce CRM Audit | Ref: AUD-E9921..E9932

Access pattern outside normal 8:30AM-5PM branch hours. No corresponding service tickets.
#43/28/2026, 9:15:00 AMnew_payee

Two beneficiary accounts created same day as $85K and $92K transfers

Source: Symitar Core Banking | Ref: BEN-A1104,A1105

New beneficiary creation proximate to large outbound wires — structuring indicator per BSA guidelines.
#53/20/2026, 12:00:00 AMtraining_missed

Employee overdue on annual BSA/AML compliance training (due Mar 15)

Source: UKG Learning Management | Ref: TRN-4421

Non-completion of mandatory compliance training elevates insider risk context.
RisksRadarAI — Cross-Domain Risk Intelligence for Regulated Enterprises