Article Details
Scrape Timestamp (UTC): 2025-08-05 12:42:30.114
Original Article Text
Click to Toggle View
Cisco discloses data breach impacting Cisco.com user accounts. Cisco has disclosed that cybercriminals stole the basic profile information of users registered on Cisco.com following a voice phishing (vishing) attack that targeted a company representative. After becoming aware of the incident on July 24th, the networking equipment giant discovered that the attacker tricked an employee and gained access to a third-party cloud-based Customer Relationship Management (CRM) system used by Cisco. This allowed the threat actor to steal the personal and user information of individuals with Cisco.com user accounts, including names, organization names, addresses, Cisco-assigned user IDs, email addresses, phone numbers, and account metadata such as creation dates. However, the company said that the attacker didn't obtain "organizational customers' confidential or proprietary information, or any passwords or other types of sensitive information." Cisco added that the incident didn't impact its products or services, and no other Cisco CRM system instances were affected. "Upon learning of the incident, the actor's access to that CRM system instance was immediately terminated and Cisco commenced an investigation. Cisco has engaged with data protection authorities and notified affected users where required by law," the company said. "We are implementing further security measures to mitigate the risk of similar incidents occurring in the future, including re-educating personnel on how to identify and protect against potential vishing attacks." Cisco has yet to disclose how many individuals had their personal and user account information stolen in the incident, and whether the attackers requested a ransom in exchange for not leaking the stolen data online. A Cisco spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today. In October, Cisco also had to take its public DevHub portal offline after a threat actor known as IntelBroker leaked "non-public" data on the BreachForums hacking forum. One month later, the company confirmed that the threat actor downloaded the files from a misconfigured public-facing DevHub portal, including some belonging to CX Professional Services customers. Red Report 2025: Analyzing the Top ATT&CK Techniques Used by 93% of Malware Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems. Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.
Daily Brief Summary
Cisco disclosed a data breach involving basic profile information of Cisco.com user accounts following a voice phishing attack.
An attacker accessed a third-party cloud-based Customer Relationship Management (CRM) system through social engineering, targeting a Cisco employee.
Stolen data included names, organization names, addresses, Cisco-assigned user IDs, email addresses, phone numbers, and account metadata.
The breach did not impact Cisco's products, services, or other CRM system instances, nor did it involve passwords or sensitive corporate information.
Cisco terminated the attacker's access to the CRM system upon discovery and initiated an investigation.
Measures are being implemented to enhance security and educate employees on recognizing and preventing vishing attacks.
Cisco has engaged with data protection authorities and has begun notifying affected individuals as required by law.
The exact number of affected users and whether attackers demanded a ransom remains undisclosed.