{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee"},"incident":{"title":"Cisco breached after vishing and MFA fatigue against an employee","date":"2022-05-24","date_precision":"day","victim_org":"Cisco Systems","sector":"Technology","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_note":"No financial loss disclosed; Cisco said no impact to its business operations, products or supply chain.","records_affected":null,"threat_actor":"Initial access broker linked to UNC2447, Lapsus$ and Yanluowang","summary":"Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.","how_it_worked":"Credentials saved in Chrome were synchronised to the employee's personal Google account, which the attacker compromised. Holding valid corporate credentials, the attacker triggered a stream of MFA push prompts to wear the user down, while simultaneously calling them in English with a plausible accent posing as support from trusted organisations. The employee eventually approved one push, giving the attacker VPN access. They then enrolled new MFA devices, escalated to administrative privileges, added backdoor accounts, and used remote access tooling and LogMeIn/TeamViewer to maintain persistence, repeatedly attempting to return after eviction.","lessons":"Number matching or FIDO2 keys instead of simple push approval, plus blocking browser credential sync to personal accounts on managed devices, would have closed both halves of this chain.","confidence":"Confirmed","sources":[{"title":"Cisco Talos shares insights related to recent cyber attack on Cisco","url":"https://blog.talosintelligence.com/recent-cyber-attack/","publisher":"Cisco Talos"},{"title":"Cisco Confirms Network Breach Via Hacked Employee Google Account","url":"https://threatpost.com/cisco-network-breach-google/180385/","publisher":"Threatpost"},{"title":"Cisco network hack: Voice phishing and MFA fatigue gave attacker access","url":"https://www.thestack.technology/cisco-network-hack-voice-phishing-mfa-fatigue/","publisher":"The Stack"}],"entry_type":"incident","slug":"2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cisco-breached-after-vishing-and-mfa-fatigue-against-an-employee"}}