Cisco confirms security incident after hacker offers to sell data

Cisco confirms security incident after hacker offers to sell data

Networking equipment provider Cisco confirmed it had information stolen after reports emerged that some of its data was offered for sale on a popular cybercrime forum. The seller, a hacker known as “IntelBroker,” posted about a “Cisco breach” on October 14, claiming to have obtained a wide range of sensitive data.

IntelBroker alleged that the stolen files included GitHub and SonarQube projects, source code, hardcoded credentials, confidential documents, Jira tickets, encryption keys, API tokens, AWS private buckets, certificates, and more. The hacker also claimed to have access to data from major corporations such as Microsoft, AT&T, Verizon, Chevron, BT, SAP, T-Mobile, and Bank of America.

As proof, IntelBroker shared screenshots of management interfaces, internal documents, source code, and databases that purportedly held customer information.

Following an internal investigation, Cisco said that its systems had not been breached. In a statement, the company explained that the stolen data originated from a public-facing DevHub environment, a resource center that hosts software code, scripts, and other materials intended for customer use.

“Based on our investigations, we are confident that there has been no breach of our systems,” Cisco said in its security incident report. “We have determined that the data in question is on a public-facing DevHub environment—a Cisco resource center that enables us to support our community by making available software code, scripts, etc. for customers to use as needed.”

Cisco acknowledged that a small number of files, which were not intended for public download, had been accessed and potentially published. However, the company stated that there is no evidence to suggest that sensitive personal information (PII) or financial data had been compromised. As a precaution, Cisco has temporarily disabled public access to the DevHub site as the investigation continues.

Back to the list

Latest Posts

Critical vBulletin vulnerability exploited in the wild

Critical vBulletin vulnerability exploited in the wild

CVE-2025-48827 and CVE-2025-48828 affect vBulletin versions 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 running on PHP 8.1 or newer.
2 June 2025
BitMEX crypto exchange targeted in Lazarus phishing attack

BitMEX crypto exchange targeted in Lazarus phishing attack

One of BitMEX's employees was targeted on LinkedIn by a fake recruiter promoting a job at an NFT project.
2 June 2025
Hackers target Korean internet cafés with CoinMiner attacks using Gh0st RAT

Hackers target Korean internet cafés with CoinMiner attacks using Gh0st RAT

The attackers focused on internet café systems running specialized management software used to track customer usage and automate billing.
2 June 2025