What happened
Cisco Duo notified customers that on 1 April 2024 a threat actor phished an employee of one of its telephony suppliers, obtained their credentials and downloaded MFA SMS and VoIP message logs covering 1 to 31 March 2024. The logs contained phone numbers, carriers, countries, states and metadata such as timestamps and message types, but not message content. The supplier invalidated the credentials, investigated and added safeguards including additional security awareness training.
How the deception worked
The attack did not target Duo at all; it targeted the intermediary that physically delivers Duo's SMS one-time codes, an organisation most Duo customers had never heard of. A single employee's credentials were enough to reach the message log store. The stolen data is second-order ammunition rather than direct access: knowing which phone number belongs to which enterprise user, on which carrier, and when they authenticate, is precisely what a SIM-swap or help-desk-impersonation crew needs to build a convincing call and to time it against a real login.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
Move off SMS as an MFA channel where possible, and require phishing-resistant authentication and log-access controls from downstream communications suppliers.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.