Cisco
Disclosed Aug 10, 20224 years agoConfirmed
Yanluowang-linked attacker breaches Cisco via employee's synced Google account
Cisco Talos said an attacker got an employee's saved credentials through a compromised personal Google account and used voice phishing and MFA push fatigue to access the VPN. The only confirmed exfiltration was a Box folder and employee authentication data from Active Directory.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Aug 10, 2022 |
| Attack | Phishing |
| Data exposed | Internal documents, Credentials and tokens |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Cisco Talos shares insights related to recent cyber attack on Ciscoblog.talosintelligence.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Aug 10, 2022 |
Other breaches at Cisco
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Cisco source code reportedly stolen using Trivy supply-chain credentialsMar 315 months agoSupply chainUnverified | Mar 315 months ago | Supply chain | Tech | Unverified | Unknown |
| Vishing attack on Cisco CRM exposes Cisco.com user profilesAug 4, 20251 year agoPhishingUnverified | Aug 4, 20251 year ago | Phishing | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.