Original Article Text

Click to Toggle View

Cisco investigates breach after stolen data for sale on hacking forum. Cisco has confirmed to BleepingComputer that it is investigating recent claims that it suffered a breach after a threat actor began selling allegedly stolen data on a hacking forum. "Cisco is aware of reports that an actor is alleging to have gained access to certain Cisco-related files," a Cisco spokesperson told BleepingComputer. "We have launched an investigation to assess this claim, and our investigation is ongoing." This statement comes after a well-known threat actor named "IntelBroker" said that he and two others called "EnergyWeaponUser and "zjj" breached Cisco on June 10, 2024, and stole a large amount of developer data from the company. "Compromised data: Github projects, Gitlab Projects, SonarQube projects, Source code, hard coded credentials, Certificates, Customer SRCs, Cisco Confidential Documents, Jira tickets, API tokens, AWS Private buckets, Cisco Technology SRCs, Docker Builds, Azure Storage buckets, Private & Public keys, SSL Certificates, Cisco Premium Products & More!," reads the post to a hacking forum. IntelBroker also shared samples of the alleged stolen data, including a database, customer information, various customer documentation, and screenshots of customer management portals. However, the threat actor did not provide further details about how the data was obtained. In June, IntelBroker began selling or leaking data from numerous companies, including T-Mobile, AMD, and Apple. Sources familiar with the attack told BleepingComputer it was stolen from a third-party managed services provider for DevOps and software development. It is unknown if the Cisco breach is related to the previous June breaches. BleepingComputer again contacted this third-party vendor to confirm if they suffered a cyberattack but has not received a reply.

Daily Brief Summary

DATA BREACH // Cisco Investigates Potential Data Breach Involving Stolen Developer Data

Cisco confirms investigation into a potential data breach after reports surfaced of data being sold on a hacking forum.

Alleged stolen data includes Github, Gitlab projects, source code, hard-coded credentials, certificates, and more.

The data was reportedly breached on June 10, 2024, by a threat actor known as "IntelBroker" and accomplices.

IntelBroker shared samples of the stolen data, which encompass customer information and various internal Cisco documents.

The breach could be linked to a wider June cyberattack on several major companies, possibly through a third-party managed services provider.

Cisco has not yet confirmed the specifics of how their data was accessed or fully detailed the extent of the breach.

No confirmation yet from the third-party service provider suspected of being the attack vector in the Cisco and other related data compromises.