logo

Fire in the Cisco! Networking giant's Duo MFA message logs stolen in phish attack

ID: 927f0463-ae18-5a9b-ba1a-0c1feac499e0

STIX ID: report--927f0463-ae18-5a9b-ba1a-0c1feac499e0

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2024-04-17

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cisco warned that a Duo telephony subcontractor suffered a phishing-driven credential compromise on April 1 that allowed attackers to download SMS message logs (phone numbers, countries/states, timestamps, carriers) for messages sent in March 2024, though message content was not accessed. Separately, Cisco Talos is tracking a global, TOR-sourced increase in brute-force/password-spray activity since mid-March targeting VPNs, web authentication interfaces, and SSH across multiple vendors; Cisco advises logging, hardening default VPN profiles, and blocking malicious sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.