Skip to content

Cisco

Disclosed Aug 10, 20224 years agoConfirmed

Official notice

Yanluowang-linked attacker breaches Cisco via employee's synced Google account

Cisco Talos said an attacker got an employee's saved credentials through a compromised personal Google account and used voice phishing and MFA push fatigue to access the VPN. The only confirmed exfiltration was a Box folder and employee authentication data from Active Directory.

What is known

People affectedNot stated in the sources we have
DisclosedAug 10, 2022
AttackPhishing
Data exposedInternal documents, Credentials and tokens
SectorTech · US
StatusConfirmed

Sources

Source
Cisco Talos shares insights related to recent cyber attack on Ciscoblog.talosintelligence.com · The organization

Notices filed

WhereFiledPeople
ResearchtotalAug 10, 2022

Other breaches at Cisco

BreachAffected
Cisco source code reportedly stolen using Trivy supply-chain credentialsMar 315 months agoSupply chainUnverifiedUnknown
Vishing attack on Cisco CRM exposes Cisco.com user profilesAug 4, 20251 year agoPhishingUnverifiedUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Cisco

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.