Key Takeaways
- Yanluowang ransomware gang gained unauthorized access to Cisco Systems and exfiltrated approximately 2.8 GB of data, comprising around 3,100 files. (Forbes)
- This attack was carried out using social engineering to defeat MFA controls.
Introduction
Cisco confirmed a security incident in which attackers gained access via a compromised employee account and social engineering.
The case sheds light on how credential syncing, MFA fatigue attacks, and user-targeted deception are used to create opportunities for threat actors.
It also shows the importance of pairing strong security controls with user awareness and rapid response.
How the Cisco Breach Happened
U.S. networking giant Cisco Systems was breached, the company confirmed on Wednesday, May 24, 2022, after Yanluowang ransomware operators claimed the attack on their leak site.
"Initial access to the Cisco VPN was achieved via the successful compromise of a Cisco employee's personal Google account," Cisco Talos stated. "The user had enabled password syncing via Google Chrome and had stored their Cisco credentials in their browser, enabling that information to synchronize to their Google account."
According to Cisco, "During the investigation, it was determined that a Cisco employee's credentials were compromised after an attacker gained control of a personal Google account where credentials saved in the victim's browser were being synchronized."
The malicious actor carried out several complex voice phishing attacks against the victim, impersonating a variety of reputable companies to persuade the victim to accept push notifications for multi-factor authentication (MFA) initiated by the adversary.
The attacker eventually convinced the employee to approve MFA push requests, which gave them VPN access under the targeted user’s account.
Claimed Data Theft
However, BleepingComputer reported that last week, the ransomware gang sent them an email containing the directory list of the data they had stolen from the Cisco hack.
Yanluowang claimed to have stolen approximately 3,100 files, totaling 2.8 GB of data. The stolen files included engineering drawings, non-disclosure agreements, and data dumps.
Cisco also stated, "We assess with moderate to high confidence that this attack was conducted by an adversary that has been previously identified as an initial access broker (IAB) with ties to the UNC2447 cybercrime gang, Lapsus$ threat actor group, and Yanluowang ransomware operators."
In addition, the company stated, “Following the recent breach, it has implemented additional measures to safeguard its systems.” Cisco also said they are sharing this incident in hopes of helping other organizations protect the broader security community.
Key Risks Exposed by the Incident
A number of security risks were identified after the Cisco incident that organizations should address to reduce the potential impact. These include:
- Saving credentials in browsers and syncing them to personal accounts. This can create unnecessary exposure.
- Repeated prompts and social engineering can abuse MFA push notifications.
- Compromise of a personal account can provide access to corporate systems.
- Attackers usually target users rather than exploiting technical vulnerabilities.
- Delayed detection can increase the impact of unauthorized access.
What Organizations Can Learn
Organizations can take several steps to reduce the likelihood of similar incidents.
- Strengthen MFA controls to reduce push approval abuse.
- Restrict credential storage in browsers and personal accounts.
- Monitor unusual VPN logins and repeated MFA prompts.
- Train employees to report suspicious calls and MFA requests.
- Apply least-privilege access controls for sensitive systems.
- Quickly investigate abnormal identity activity.
Conclusion
The Cisco incident shows that attackers do not always rely on advanced exploits to gain access. They can bypass defenses through compromised personal accounts, stored credentials, and repeated MFA push requests.
Attackers often succeed by exploiting user trust and weak identity controls rather than technical vulnerabilities. SafeAeon helps organizations review identity security controls, reduce credential exposure, and strengthen monitoring to detect suspicious access attempts early.