Cisco Hacked - User Data Stolen
The leading multinational technology conglomerate Cisco Systems, best known for its networking hardware, software and telecommunications equipment was first made aware of a hacking incident on July 24th which involved a criminal actor targeting a Cisco representative through a voice phishing attack, which is also called vishing.
According to reports, the hacker was able to access and export a subset of basic profile information from one instance of a third-party, cloud-based Customer Relationship Management (CRM) system that Cisco uses.
This is a fruther emebarassing incident invloving penetration of Cisco infatructure, most notably one earlier this year when Salt Typhoon hackers gained access to core US telecoms infrastructure through Cisco devices, then used that infrastructure to extract information.
On its discovery that the hacker had access to that CRM system it was immediately isolataed and Cisco commenced an investigation, which has now now determined that the exported data primarily consisted of basic account profile information of individuals who registered for a user account on Cisco.com.
This included their name, organisation name, address, Cisco assigned user ID, email address, phone number, and account-related metadata, such as creation date.
The company said that the intrusion was isolated to one specific CRM system and that no other internal systems, products, or services were affected. They say the hacker did not obtain any of our organisational customers’ confidential or proprietary information, or any passwords or other types of sensitive information. Cisco has engaged with data protection authorities and notified affected users where required by US law.
Cisco say they are implementing further security measures to mitigate the risk of similar incidents occurring in the future, including re-educating personnel on how to identify and protect against potential vishing attacks.
The company issued an apology for the incident. “We apologise for any inconvenience or concern that this incident may have caused,” Cisco stated, encouraging customers and partners with further questions to get in touch with their designated account teams for support.
Cisco | Security Week | Bleeping Computer | Security Affairs | Cybersecurity News
Image: @Cisco
You Might Also Read:
Attacks Against Cisco Firewall Platforms:
If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.
- Individual £5 per month or £50 per year. Sign Up
- Multi-User, Corporate & Library Accounts Available on Request
- Inquiries: Contact Cyber Security Intelligence
Cyber Security Intelligence: Captured Organised & Accessible