Cisco Duo's Multifactor Authentication Service Breached
ID: c73776db-a216-512c-955d-e18a7f38175d
STIX ID: report--c73776db-a216-512c-955d-e18a7f38175d
Feed Name: Dark Reading
Date Published: 2024-04-15
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
A third-party telephony provider that handles SMS and VOIP for Cisco Duo was compromised via social engineering and stolen employee credentials; attackers downloaded SMS message logs for users between March 1 and March 31, 2024. The logs contained phone numbers, carriers, country/state, timestamps and other metadata (but not message content); Cisco has advised customers to notify affected users and remain vigilant for follow-on phishing attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
