Monday, April 7, 2025
HomeData BreachCitrix Hacked - Terabytes of Sensitive data Stolen by Iranian Hackers

Citrix Hacked – Terabytes of Sensitive data Stolen by Iranian Hackers

Published on

SIEM as a Service

Follow Us on Google News

Citrix hacked, Yes, Citrix suffered a massive data breach and the company believes that the attackers may have stolen atleast 6 TB to 10 TB of data by compromise the Citrix internal systems.

Citrix Systems, Inc.a well-known software company that provides server, application and desktop virtualization, networking, software as a service, and cloud computing technologies for NASA, FBI etc.

FBI claimed that Citrix Hacked by international cybercriminals who have gained access to the internal system and stole the sensitive business documents.

- Advertisement - Google News

Citrix said, “it was unclear about the specific documents that were stolen,
Despite this incident, there was no further indication that we encountered any Citrix product or service was compromised.”

Researchers believe that Citrix hacked by Iran-base organized cybercrime group called Iridium who may have stolen atleast 6-10 TB of highly sensitive data that belongs to the project data of aerospace industry, the FBI, NASA and Saudi Arabia’s state-owned oil company.

IRIDIUM has already hit record of more than 200 government agencies, oil and gas companies, and technology companies including Citrix.

Threat actors leveraged a combination of tools, techniques and procedures, allowing them to conduct targeted network intrusion to access The internal network.

FBI made a statement that the attackers used a tactic known as password spraying, a technique used for a cyber attack against the weak password to compromise the first level of security then they move ahead and work to break the aditional security layers.

Accodring to the Citrix statement, Citrix is moving as quickly as possible, with the understanding that these investigations are complex, dynamic and require time to conduct properly. In investigations of cyber incidents, the details matter, and we are committed to communicating appropriately when we have what we believe is credible and actionable information.

Citrix also deployed a forensic investigation team to involve with this incident and let them protect the internal data and also and continue to cooperate with the FBI and other law enforcement authorities.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

5 Best Workplace Practices To Prevent Data Breach

Houzz Suffers a Data Breach, Alerts Users to Change Password

Airbus Data Breach – Hackers Stolen Employee Sensitive & Personal Data

773 Million Credentials of Email & Password leaked in Massive Data Breach – Biggest Data Dump Ever Found on a Decade

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploit Toll Payment Services in Widespread Hacking Campaign

In a sophisticated cybercrime operation, the Smishing Triad, a China-based group, has been identified...

Everest Ransomware Gang’s Leak Site Hacked and Defaced

TechCrunch has uncovered a concerning development in consumer-grade spyware: a stealthy Android monitoring app...

ToddyCat Attackers Exploited ESET Command Line Scanner Vulnerability to Conceal Their Tool

In a sophisticated cyberattack, the notorious ToddyCat APT group utilized a previously unknown vulnerability...

Threat Actors Use VPS Hosting Providers to Deliver Malware and Evade Detection

Cybercriminals are intensifying phishing campaigns to spread the Grandoreiro banking trojan, targeting users primarily...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

20-Year-Old Scattered Spider Hacker Pleads Guilty in Major Ransomware Case

A 20-year-old Noah Urban, a resident of Palm Coast, Florida, pleaded guilty to a...

State Bar of Texas Confirms Data Breach, Begins Notifying Affected Consumers

The State Bar of Texas has confirmed a data breach following the detection of...

Oracle Confirms The Data Breach- Starts Initiating Client Notifications

Oracle Corporation has confirmed a data breach involving its older Gen 1 servers, marking...