Wednesday, April 30, 2025
Homecyber securityCisco Duo Data Breach: Hackers Stolen VoIP & SMS for MFA

Cisco Duo Data Breach: Hackers Stolen VoIP & SMS for MFA

Published on

SIEM as a Service

Follow Us on Google News

Cisco’s Duo Security, a leading multi-factor authentication (MFA) service, has suffered a significant data breach.

The April 1, 2024, incident involved unauthorized access to telephony data used for MFA purposes.

The breach was produced through a sophisticated phishing attack that compromised a telephony provider’s employee credentials.

- Advertisement - Google News

The attackers exploited this access to download a set of MFA SMS message logs associated with Duo accounts.

These logs contained sensitive information, including phone numbers, carriers, and the geographical location of the messages sent between March 1, 2024, and March 31, 2024.

Although the message content was not accessed, the breach still poses a significant privacy concern for users.

Document
Stop Advanced Phishing Attack With AI

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by other email security solutions. .

The exposed metadata could potentially be used for targeted phishing campaigns or to undermine the integrity of MFA systems by intercepting or redirecting messages.

Security Measures

Upon discovering the breach, the telephony provider, whose identity has not been disclosed, took immediate action to contain the incident.

The compromised credentials were invalidated to prevent further unauthorized access.

The provider also conducted a thorough analysis of activity logs to understand the scope of the breach.

The provider has begun implementing additional technical safeguards to bolster security and prevent future incidents.

These measures are designed to fortify defenses against social engineering attacks, increasingly becoming a vector for cyber threats.

The provider has responded proactively, notifying Cisco of the breach and committing to an ongoing investigation.

They have also taken steps to educate their employees on social engineering risks, mandating additional training to raise awareness and improve resilience against such attacks.

Cisco has communicated transparently with affected customers, offering to provide copies of the message logs obtained by the threat actor upon request.

DeepBlue Security and Intelligence recently tweeted that Cisco Duo has issued a warning about a third-party data breach that exposed SMS MFA logs.

Action for Affected Users

In light of the breach, Cisco urges all affected customers to notify their users promptly.

Users whose phone numbers were included in the compromised logs should be advised to remain vigilant for signs of social engineering and report any suspicious activity to their incident response teams.

Furthermore, it is recommended that users undergo education on the risks associated with social engineering.

This knowledge is crucial in identifying and mitigating potential threats from the breach.

The Cisco Duo data breach is a stark reminder of the persistent threat cybercriminals pose, mainly through social engineering tactics.

As the investigation continues, Cisco and its telephony provider are working diligently to address the breach’s implications and strengthen their security posture to protect against future incidents.

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Trellix Launches Phishing Simulator to Help Organizations Detect and Prevent Attacks

Trellix, a leader in cybersecurity solutions, has unveiled its latest innovation, the Trellix Phishing...

AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens

Darktrace's Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been...

Nitrogen Ransomware Uses Cobalt Strike and Log Wiping in Targeted Attacks on Organizations

Threat actors have leveraged the Nitrogen ransomware campaign to target organizations through deceptive malvertising...

Researchers Reveal Threat Actor TTP Patterns and DNS Abuse in Investment Scams

Cybersecurity researchers have uncovered the intricate tactics, techniques, and procedures (TTPs) employed by threat...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Trellix Launches Phishing Simulator to Help Organizations Detect and Prevent Attacks

Trellix, a leader in cybersecurity solutions, has unveiled its latest innovation, the Trellix Phishing...

AiTM Phishing Kits Bypass MFA by Hijacking Credentials and Session Tokens

Darktrace's Security Operations Center (SOC) in late 2024 and early 2025, cybercriminals have been...

Nitrogen Ransomware Uses Cobalt Strike and Log Wiping in Targeted Attacks on Organizations

Threat actors have leveraged the Nitrogen ransomware campaign to target organizations through deceptive malvertising...