What happened
In April 2019 Indian IT services giant Wipro confirmed that it had detected abnormal activity in a number of employee accounts caused by what it called an advanced phishing campaign. Reporting showed attackers used the compromised Wipro accounts as a launch point against the company's own customers, with the follow-on activity linked to gift-card and payment fraud. Wipro engaged an independent forensic firm and built a new private email network.
How the deception worked
Attackers ran a phishing campaign against Wipro staff and captured credentials for a number of corporate accounts. The value of those accounts was not Wipro's own data but Wipro's position as a trusted outsourcing provider with standing access into client environments. Emails sent from genuine Wipro addresses to client contacts carry an authority that no spoofed domain can match, so the compromised mailboxes became the delivery mechanism for attacks on downstream customers. The follow-on activity was financially motivated, centring on gift-card and payment fraud at the affected clients rather than espionage.
The control that would have caught it· our reading, not a claim from the sources
Managed service providers need phishing-resistant MFA on all staff accounts and customer-side monitoring of provider access, because a phished MSP mailbox is a trusted channel into every client.
Sources (2)
- Wipro admits to potential breach to employee accounts by phishing attackComputer Weekly·computerweekly.comOpen ↗
- How Not to Acknowledge a Data BreachKrebs on Security·krebsonsecurity.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.