Skip to content
NetarxImpact Database
MFA Fatigue / Push BombingNo AI reportedConfirmed

Cisco breached after vishing and MFA fatigue against an employee

Cisco Systems · Technology · United States · May 24, 2022

What happened

Cisco Talos disclosed that in May 2022 an attacker gained VPN access to Cisco's corporate network after compromising an employee's personal Google account, where browser-synced corporate credentials were stored. The attacker then combined repeated MFA push notifications with voice phishing calls impersonating trusted support organisations until the employee accepted a push. Cisco said data from a Box folder and Active Directory information were taken, and the actor was evicted before reaching product development or code-signing systems.

How the deception worked

Credentials saved in Chrome were synchronised to the employee's personal Google account, which the attacker compromised. Holding valid corporate credentials, the attacker triggered a stream of MFA push prompts to wear the user down, while simultaneously calling them in English with a plausible accent posing as support from trusted organisations. The employee eventually approved one push, giving the attacker VPN access. They then enrolled new MFA devices, escalated to administrative privileges, added backdoor accounts, and used remote access tooling and LogMeIn/TeamViewer to maintain persistence, repeatedly attempting to return after eviction.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Number matching or FIDO2 keys instead of simple push approval, plus blocking browser credential sync to personal accounts on managed devices, would have closed both halves of this chain.

Sources (3)

  1. Cisco Talos shares insights related to recent cyber attack on Cisco
    Cisco Talos·blog.talosintelligence.comOpen ↗
  2. Cisco Confirms Network Breach Via Hacked Employee Google Account
    Threatpost·threatpost.comOpen ↗
  3. Cisco network hack: Voice phishing and MFA fatigue gave attacker access
    The Stack·thestack.technologyOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.