17 July 2023

JumpCloud says it was attacked by nation-state hackers


JumpCloud says it was attacked by nation-state hackers

US-based enterprise software firm JumpCloud revealed a sophisticated nation-state threat actor is behind a security breach that hacked into the company’s systems to target a small and specific set of customers.

According to Bob Phan, chief information security officer at JumpCloud, the attack started on June 22 with a spear-phishing campaign, through which the intruders gained access to “a specific area of our infrastructure.” After detecting unusual activity on an internal orchestration system on June 27, JumpCloud reset credentials, rebuilt infrastructure and took a number of additional security measures.

A few days later, the company reset all admin API keys after discovering unusual activity in the commands framework for a small set of customers.

“Continued analysis uncovered the attack vector: data injection into our commands framework. The analysis also confirmed suspicions that the attack was extremely targeted and limited to specific customers,” Phan said, adding that the attack vector was mitigated.

While the company did not specify what country or the hacker group was responsible for the breach, it shared a list of Indicators of Compromise (IoCs) to help organizations detect similar intrusions.

Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024