cisco confirms yanluowang ransomware gang
Updated: August 16, 2022 4 Mins Reading

Cisco Confirms Breach Linked to Yanluowang Ransomware Gang

Key Takeaways

  • Yanluowang ransomware gang gained unauthorized access to Cisco Systems and exfiltrated approximately 2.8 GB of data, comprising around 3,100 files. (Forbes)
  • This attack was carried out using social engineering to defeat MFA controls.

Introduction

Cisco confirmed a security incident in which attackers gained access via a compromised employee account and social engineering.

The case sheds light on how credential syncing, MFA fatigue attacks, and user-targeted deception are used to create opportunities for threat actors.

It also shows the importance of pairing strong security controls with user awareness and rapid response.

How the Cisco Breach Happened

U.S. networking giant Cisco Systems was breached, the company confirmed on Wednesday, May 24, 2022, after Yanluowang ransomware operators claimed the attack on their leak site.

"Initial access to the Cisco VPN was achieved via the successful compromise of a Cisco employee's personal Google account," Cisco Talos stated. "The user had enabled password syncing via Google Chrome and had stored their Cisco credentials in their browser, enabling that information to synchronize to their Google account."

According to Cisco, "During the investigation, it was determined that a Cisco employee's credentials were compromised after an attacker gained control of a personal Google account where credentials saved in the victim's browser were being synchronized."

The malicious actor carried out several complex voice phishing attacks against the victim, impersonating a variety of reputable companies to persuade the victim to accept push notifications for multi-factor authentication (MFA) initiated by the adversary.

The attacker eventually convinced the employee to approve MFA push requests, which gave them VPN access under the targeted user’s account.

Typical Ransomware Attack Chain

Claimed Data Theft

However, BleepingComputer reported that last week, the ransomware gang sent them an email containing the directory list of the data they had stolen from the Cisco hack.

Yanluowang claimed to have stolen approximately 3,100 files, totaling 2.8 GB of data. The stolen files included engineering drawings, non-disclosure agreements, and data dumps.

Cisco also stated, "We assess with moderate to high confidence that this attack was conducted by an adversary that has been previously identified as an initial access broker (IAB) with ties to the UNC2447 cybercrime gang, Lapsus$ threat actor group, and Yanluowang ransomware operators."

In addition, the company stated, “Following the recent breach, it has implemented additional measures to safeguard its systems.” Cisco also said they are sharing this incident in hopes of helping other organizations protect the broader security community.

Key Risks Exposed by the Incident

A number of security risks were identified after the Cisco incident that organizations should address to reduce the potential impact. These include:

  • Saving credentials in browsers and syncing them to personal accounts. This can create unnecessary exposure.
  • Repeated prompts and social engineering can abuse MFA push notifications.
  • Compromise of a personal account can provide access to corporate systems.
  • Attackers usually target users rather than exploiting technical vulnerabilities.
  • Delayed detection can increase the impact of unauthorized access.

What Organizations Can Learn

Organizations can take several steps to reduce the likelihood of similar incidents.

How to Prevent Identity and Ransomware Attacks
  • Strengthen MFA controls to reduce push approval abuse.
  • Restrict credential storage in browsers and personal accounts.
  • Monitor unusual VPN logins and repeated MFA prompts.
  • Train employees to report suspicious calls and MFA requests.
  • Apply least-privilege access controls for sensitive systems.
  • Quickly investigate abnormal identity activity.
secure-backup-readiness

Conclusion

The Cisco incident shows that attackers do not always rely on advanced exploits to gain access. They can bypass defenses through compromised personal accounts, stored credentials, and repeated MFA push requests.

Attackers often succeed by exploiting user trust and weak identity controls rather than technical vulnerabilities. SafeAeon helps organizations review identity security controls, reduce credential exposure, and strengthen monitoring to detect suspicious access attempts early.

Close Detection Gaps Before Attackers Exploit Them

Improve detection and response across endpoint, network, and cloud with 24×7 managed security operations.

Summarize this post

Frequently Asked Questions About the Cisco Security Incident

Clear answers to common questions security leaders and teams regularly ask.

Attackers gained access after compromising an employee’s personal Google account, where Cisco credentials synced from the browser were stored. They then used social engineering to gain MFA approval.
An MFA fatigue attack is a technique in which an attacker repeatedly sends authentication prompts until the user accepts one under pressure or deception.
The threat group claimed to have stolen files that included engineering drawings, non-disclosure agreements, and data dumps.
This incident showed how credentials synced to personal accounts can expose corporate systems.
Organizations can take a few essential steps, such as strengthening their MFA controls and restricting the storage of credentials in web browsers and personal accounts. Apart from that, fast monitoring of suspicious login activity is also crucial, along with employee training, so that they can identify social engineering attempts.

Discover More Blogs