{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu"},"incident":{"slug":"2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu","title":"Wipro employee accounts phished and used to attack the IT giant's own customers","date":"2019-04","date_precision":"month","year":2019,"victim_org":"Wipro Limited","sector":"Technology","country":"India","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Supply Chain Compromise","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.","how_it_worked":"Attackers ran a phishing campaign against Wipro staff and captured credentials for a number of corporate accounts. The value of those accounts was not Wipro's own data but Wipro's position as a trusted outsourcing provider with standing access into client environments. Emails sent from genuine Wipro addresses to client contacts carry an authority that no spoofed domain can match, so the compromised mailboxes became the delivery mechanism for attacks on downstream customers. The follow-on activity was financially motivated, centring on gift-card and payment fraud at the affected clients rather than espionage.","lessons":"Managed service providers need phishing-resistant MFA on all staff accounts and customer-side monitoring of provider access, because a phished MSP mailbox is a trusted channel into every client.","confidence":"Confirmed","sources":[{"title":"Wipro admits to potential breach to employee accounts by phishing attack","url":"https://www.computerweekly.com/news/252461760/Wipro-admits-to-potential-breach-to-employee-accounts-by-phishing-attack","publisher":"Computer Weekly"},{"title":"How Not to Acknowledge a Data Breach","url":"https://krebsonsecurity.com/2019/04/how-not-to-acknowledge-a-data-breach/comment-page-1/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-wipro-employee-accounts-phished-and-used-to-attack-the-it-giant-s-own-cu"}}