21 October 2024

Cisco confirms security incident after hacker offers to sell data


Cisco confirms security incident after hacker offers to sell data

Networking equipment provider Cisco confirmed it had information stolen after reports emerged that some of its data was offered for sale on a popular cybercrime forum. The seller, a hacker known as “IntelBroker,” posted about a “Cisco breach” on October 14, claiming to have obtained a wide range of sensitive data.

IntelBroker alleged that the stolen files included GitHub and SonarQube projects, source code, hardcoded credentials, confidential documents, Jira tickets, encryption keys, API tokens, AWS private buckets, certificates, and more. The hacker also claimed to have access to data from major corporations such as Microsoft, AT&T, Verizon, Chevron, BT, SAP, T-Mobile, and Bank of America.

As proof, IntelBroker shared screenshots of management interfaces, internal documents, source code, and databases that purportedly held customer information.

Following an internal investigation, Cisco said that its systems had not been breached. In a statement, the company explained that the stolen data originated from a public-facing DevHub environment, a resource center that hosts software code, scripts, and other materials intended for customer use.

“Based on our investigations, we are confident that there has been no breach of our systems,” Cisco said in its security incident report. “We have determined that the data in question is on a public-facing DevHub environment—a Cisco resource center that enables us to support our community by making available software code, scripts, etc. for customers to use as needed.”

Cisco acknowledged that a small number of files, which were not intended for public download, had been accessed and potentially published. However, the company stated that there is no evidence to suggest that sensitive personal information (PII) or financial data had been compromised. As a precaution, Cisco has temporarily disabled public access to the DevHub site as the investigation continues.

Back to the list

Latest Posts

Russian cyber spies target Georgia’s government and critical  infrastructure

Russian cyber spies target Georgia’s government and critical infrastructure

In addition to espionage, Moscow gained the capability to sabotage Georgia’s power and communications networks.
22 October 2024
Internet Archive breached again via stolen access tokens

Internet Archive breached again via stolen access tokens

The attackers reportedly were able to gain access to over 800,000 support tickets.
21 October 2024
Cisco confirms security incident after hacker offers to sell data

Cisco confirms security incident after hacker offers to sell data

Cisco said that a small number of files, which were not intended for public download, had been accessed and potentially published.
21 October 2024