2022-05-24 (incident), The date Cisco became aware of a potential compromise; Cisco Talos published its analysis on 10 August 2022. · US · Cisco
Cisco employee targeted by vishing and MFA fatigue, 2022
Disclosed by the affected organisation.
An attacker took over a Cisco employee's personal Google account, where saved browser passwords, including Cisco credentials, were synchronised. To get past MFA the attacker made voice phishing calls over several days, posing as trusted support organisations, and sent repeated push requests until one was accepted. Cisco Talos said the attacker reached the VPN, escalated privileges and took the contents of one Box folder and Active Directory authentication data, but no ransomware was deployed.
Timeline
- 2022-05-24 Cisco becomes aware of a potential compromise and begins its response.
- 2022-08-10 Cisco Talos publishes its analysis, attributing the attack to an initial access broker with ties to UNC2447, Lapsus$ and Yanluowang operators.
Lessons
- Block staff from syncing corporate passwords into personal browser profiles or personal cloud accounts.
- Train staff that real support teams do not call to ask them to approve MFA prompts they did not start.
- Require verification before a new MFA device is enrolled; the attacker here enrolled a series of new devices.
Scam types: MFA fatigue (push bombing) · Techniques: Voice phishing (vishing)
Sources
- Cisco Talos shares insights related to recent cyber attack on Cisco (Company disclosure, primary, accessed 2026-09-24)