Skip to content

2022-05-24 (incident), The date Cisco became aware of a potential compromise; Cisco Talos published its analysis on 10 August 2022. · US · Cisco

Cisco employee targeted by vishing and MFA fatigue, 2022

Disclosed by the affected organisation.

An attacker took over a Cisco employee's personal Google account, where saved browser passwords, including Cisco credentials, were synchronised. To get past MFA the attacker made voice phishing calls over several days, posing as trusted support organisations, and sent repeated push requests until one was accepted. Cisco Talos said the attacker reached the VPN, escalated privileges and took the contents of one Box folder and Active Directory authentication data, but no ransomware was deployed.

Timeline

  1. 2022-05-24 Cisco becomes aware of a potential compromise and begins its response.
  2. 2022-08-10 Cisco Talos publishes its analysis, attributing the attack to an initial access broker with ties to UNC2447, Lapsus$ and Yanluowang operators.

Lessons

Scam types: MFA fatigue (push bombing) · Techniques: Voice phishing (vishing)

Sources

  1. Cisco Talos shares insights related to recent cyber attack on Cisco (Company disclosure, primary, accessed 2026-09-24)