{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs"},"incident":{"title":"Cisco Duo telephony supplier phished, exposing a month of MFA SMS logs","date":"2024-04-01","date_precision":"day","victim_org":"Cisco Duo (via an unnamed telephony supplier)","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.","how_it_worked":"The attack did not target Duo at all; it targeted the intermediary that physically delivers Duo's SMS one-time codes, an organisation most Duo customers had never heard of. A single employee's credentials were enough to reach the message log store. The stolen data is second-order ammunition rather than direct access: knowing which phone number belongs to which enterprise user, on which carrier, and when they authenticate, is precisely what a SIM-swap or help-desk-impersonation crew needs to build a convincing call and to time it against a real login.","lessons":"Move off SMS as an MFA channel where possible, and require phishing-resistant authentication and log-access controls from downstream communications suppliers.","confidence":"Confirmed","sources":[{"title":"Cisco Duo warns telephony supplier data breach exposed MFA SMS logs","url":"https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-cisco-duo-telephony-supplier-phished-exposing-a-month-of-mfa-sms-logs"}}