Skip to content

Cisco

Disclosed Mar 31, 20265 months agoUnverified

Cisco source code reportedly stolen using Trivy supply-chain credentials

Attackers linked to TeamPCP reportedly used credentials stolen through the compromised Trivy GitHub Action to breach Cisco's development environment and copy code from more than 300 GitHub repositories plus AWS keys. Cisco did not respond to requests for comment.

What is known

People affectedNot stated in the sources we have
DisclosedMar 31, 2026
AttackSupply chain
Data exposedSource code, API keys
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Part ofTrivy (2026)

Sources

Source
Cisco source code stolen in Trivy-linked dev environment breachbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalMar 31

Same campaign

Other breaches at Cisco

BreachAffected
Vishing attack on Cisco CRM exposes Cisco.com user profilesAug 4, 20251 year agoPhishingUnverifiedUnknown
Yanluowang-linked attacker breaches Cisco via employee's synced Google accountAug 10, 20224 years agoPhishingUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Cisco

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.