Press releases

Yanluowang Gang ransomware hacked into the Cisco corporate network

The Yanluowang ransomware gang hacked Cisco's corporate network in late May and stole corporate information, the company said in a statement.

According to an investigation by Cisco Security Incident Response (CSIRT) and Cisco Talos, a hacker compromised the credentials of a Cisco employee after detecting a personal Google account in which credentials saved in the victim's browser were synchronized.

Cisco claims that an attacker targeted one of its employees and only managed to steal files from a Box folder linked to that employee's account and the employee's authentication information from Active Directory. According to the company, the data stored in the Box folder was not sensitive.

The hackers hijacked a Cisco employee's personal Google account, which contained browser-synced credentials, and used those credentials to log into the Cisco network.

After a series of sophisticated voice phishing attacks carried out by the Yanluowang gang, the hacker convinced the Cisco employee to accept multi-factor authentication (MFA) push alerts.

Innovation newsletter
Don't miss the most important news on innovation. Sign up to receive them by email.

The Yanluowang ransomware organization claimed responsibility for the attack and claimed to have stolen approximately 3.000 files totaling 2,8 Gb in size. According to the file names disclosed by the hackers, they may have stolen NDA, source code, VPN client and other data.

The attack did not use a ransomware that encrypts files. After being removed from Cisco's systems, the hackers sent an email to Cisco executives, but it contained no explicit threats or ransom demands.

  

Ercole Palmeri: Innovation addicted

Innovation newsletter
Don't miss the most important news on innovation. Sign up to receive them by email.

Latest Articles

Google's new artificial intelligence can model DNA, RNA and "all the molecules of life"

Google DeepMind is introducing an improved version of its artificial intelligence model. The new improved model provides not only…

May 9, 2024

Exploring Laravel's Modular Architecture

Laravel, famous for its elegant syntax and powerful features, also provides a solid foundation for modular architecture. There…

May 9, 2024

Cisco Hypershield and acquisition of Splunk The new era of security begins

Cisco and Splunk are helping customers accelerate their journey to the Security Operations Center (SOC) of the future with…

May 8, 2024

Beyond the economic side: the unobvious cost of ransomware

Ransomware has dominated the news for the last two years. Most people are well aware that attacks…

May 6, 2024

Innovative intervention in Augmented Reality, with an Apple viewer at the Catania Polyclinic

An ophthalmoplasty operation using the Apple Vision Pro commercial viewer was performed at the Catania Polyclinic…

May 3, 2024

The Benefits of Coloring Pages for Children - a world of magic for all ages

Developing fine motor skills through coloring prepares children for more complex skills like writing. To color…

May 2, 2024

The Future is Here: How the Shipping Industry is Revolutionizing the Global Economy

The naval sector is a true global economic power, which has navigated towards a 150 billion market...

May 1, 2024

Publishers and OpenAI sign agreements to regulate the flow of information processed by Artificial Intelligence

Last Monday, the Financial Times announced a deal with OpenAI. FT licenses its world-class journalism…

April 30 2024