Cisco Data Breach Attributed to Lapsus$ Ransomware Group

Share:

Analysis shows attackers breached employee credentials with voice phishing and were preparing a ransomware attack against Cisco Systems.

A month after confirming its systems were breached, networking giant Cisco reported that the attack was a failed ransomware attempt conducted on behalf of the Lapsus$ group.

The cybercriminals obtained access to Cisco’s systems with a social engineering attack that began with an attacker taking control of an employee’s personal Google account, where credentials saved in the victim’s browser were being synchronized. Then, in a series of sophisticated voice phishing attacks, the gang convinced the victim to accept multifactor authentication (MFA) push notifications, giving crooks the ability to log in to the corporate VPN as if they were the victim.

From there, the attackers were able to compromise Cisco systems, elevate privileges, drop remote access tools, deploy Cobalt Strike and other offensive malware, and add their own backdoors into the system.

ADVERTISING

“Based upon artifacts obtained, tactics, techniques, and procedures (TTPs) identified, infrastructure used, and a thorough analysis of the backdoor utilized in this attack, we assess with moderate to high confidence that this attack was conducted by an adversary that has been previously identified as an initial access broker (IAB) with ties to both UNC2447 and Lapsus$,” the Cisco Talos team explained in a Sept. 11 update on the August breach. “While we did not observe ransomware deployment in this attack, the TTPs used were consistent with ‘pre-ransomware activity,’ activity commonly observed leading up to the deployment of ransomware in victim environments.”

https://www.darkreading.com/attacks-breaches/cisco-data-breach-lapsus-ransomware-group

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:47 am, May 19, 2025
weather icon 10°C
L: 10° | H: 11°
broken clouds
Humidity: 84 %
Pressure: 1020 mb
Wind: 5 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:02 am
Sunset: 8:51 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
10° | 11°°C 0 mm 0% 11 mph 84 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fri May 23 10:00 pm
weather icon
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 7:00 am
weather icon
10° | 11°°C 0 mm 0% 6 mph 84 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
12° | 15°°C 0 mm 0% 7 mph 75 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
16° | 19°°C 0 mm 0% 9 mph 54 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
19° | 19°°C 0 mm 0% 11 mph 40 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,443.20
0.09%
Ethereum(ETH)
€2,138.32
-3.65%
Tether(USDT)
€0.89
0.00%
XRP(XRP)
€2.10
-0.60%
Solana(SOL)
€147.87
-1.29%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.196601
1.72%
Shiba Inu(SHIB)
€0.000013
0.10%
Pepe(PEPE)
€0.000012
5.20%
Peanut the Squirrel(PNUT)
€0.286584
6.73%
Scroll to Top