Cisco Data Leaked By Hacker
Cisco, a global leader in networking and cybersecurity, has confirmed that a hacker known as IntelBroker accessed and leaked 2.9 GB of data from its public-facing DevH...
On Dec. 16, a hacker known as "IntelBroker" leaked 2.9 gigabytes of files from Cisco's DevHub platform onto BreachForums, a dark web marketplace. The leaked data reportedly included source code, certificates, and internal documentation tied to Cisco products such as Catalyst, IOS, WebEx and Secure Access Service Edge. According to Cisco, the incident stemmed from a configuration error rather than a breach of its internal systems.
Data Exposure Rooted in Configuration Error
Cisco reports that the exposed data originated from devhub.cisco.com, a site intended to provide software code, templates and scripts to developers, partners and customers. While much of the platform’s content is deliberately public, Cisco states that a configuration error during a data migration process inadvertently made additional files accessible. This misstep allowed the hacker to download files that were not meant for public access.
How The Cisco Data Breach Unfolded
The issue began on Oct. 14, when IntelBroker posted screenshots of files on BreachForums, claiming to have breached Cisco’s systems. Cisco responded immediately by disabling public access to DevHub and launching an investigation. According to Cisco, the files were not obtained through a breach of internal systems but were downloaded from DevHub due to the configuration error.
Cisco states that the investigation confirmed no internal systems or enterprise environments were accessed. The company also reports that the exposed files did not contain sensitive information that could compromise its products or customer data.
Why Josh Myers Should Be The Packers’ Most Important Free Agent
These Are The 10 Highest-Grossing Christmas Movies Of All Time
After identifying the misconfiguration, Cisco says it corrected the error and restored public access to DevHub. The company engaged law enforcement and third-party forensic experts to assist in analyzing the situation. Additionally, Cisco compiled a list of files downloaded during the incident and assessed their contents for potential risks.
The December Cisco Data Leak on BreachForums
On December 18, IntelBroker leaked 2.9 gigabytes of data on BreachForums, allegedly part of a larger 4.5 terabyte trove. The leaked files reportedly included:
- Source code written in JavaScript and Python.
- Certificates and library files.
- Internal documentation tied to Cisco products.
Cisco acknowledges that some of the exposed files pertain to a limited number of Cisco CX Professional Services customers. The company states that it notified these customers directly, provided copies of the relevant files and offered assistance in assessing potential risks.
Cisco Responds To The Data Breach
Cisco outlines several actions it took in response to the incident:
- Disabling Access: Public access to DevHub was temporarily disabled while the company investigated.
- Law Enforcement Engagement: Cisco says it worked with law enforcement and engaged third-party forensic experts to analyze the incident.
- Correcting Errors: Cisco reports that it identified a misconfigured data migration script as the root cause and corrected the issue.
- Customer Notifications: According to Cisco, affected customers were notified and provided with copies of the relevant files, along with support to review any risks.
Cisco also states that it has implemented enhanced measures to prevent similar issues in the future. These include stricter controls over automation processes, improved monitoring systems for public-facing platforms and expanded quality assurance testing to identify vulnerabilities before deployment.
Cisco has been contacted for comment. This article will be updated when they respond.
This column originally appeared in Forbes.