Cybersecurity breach strikes Cisco duo’s multifactor authentication service

Cisco’s Duo multifactor authentication service has issued a warning to its users following a cybersecurity breach involving a third-party telephony service provider. The incident, which was the result of a social engineering attack, could potentially expose users to phishing schemes.

According to a report by Dark Reading, the breach occurred when threat actors obtained employee credentials from the provider that handles SMS and VOIP traffic for Cisco Duo. On April 1, unauthorized access was gained, and SMS logs were downloaded, specifically targeting certain users between March 1, 2024, and March 31, 2024. While the logs did not include the content of the messages, they contained sensitive details such as phone numbers, carriers, and the geographical data of the recipients, along with other metadata.

Read more

You may also like

More in IT

Comments are closed.