Wednesday, January 1, 2025
HomeData BreachCitrix Internal Network Hacked and Access the Most Sensitive Data for 6...

Citrix Internal Network Hacked and Access the Most Sensitive Data for 6 Month by Unknown Hackers

Published on

SIEM as a Service

Citrix finally confirms that the cybercriminals successfully compromised their internal network and accessed the most sensitive files also they removed from their network during the security breach that reported in March.

Citrix Systems, Inc.a well-known software company that provides server, application, and desktop virtualization, networking, software as a service, and cloud computing technologies for NASA, FBI, etc.

Citrix experienced a massive data breach and the company were believed that the attackers may have stolen at least 6 TB to 10 TB of data.

- Advertisement - SIEM as a Service

In March when FBI notified to Citrix regarding this incident that they believed that Iran-base organized cybercrime group called Iridium who may have stolen at least 6-10 TB of highly sensitive data that belongs to the project data of aerospace industry, the FBI, NASA, and Saudi Arabia’s state-owned oil company.

During the attack, threat actors leveraged a combination of tools, techniques, and procedures, allowing them to conduct targeted network intrusion to access The internal network.

After this incident learned by Citrix, they deployed the security experts and immediately launched an investigation.

In this case, FBI was claimed that Citrix Hacked by international cyber criminals who have gained access to the internal system and stole the sensitive business documents.

Now, Citrix Released a new statement that named as “Notice of Data Breach” to Office of the Attorney General and all the Citrix employees who were suffered by this data breach.

Based on the investigation report, Citrix confirmed that the cybercriminals had intermittent access to our network between October 13, 2018, and March 8, 2019, and that they removed files from Citrix internal systems.

Stolen data contains current and former employees and, in limited cases, information about beneficiaries and/or dependents including names, Social Security numbers, and financial information.

“In order to find out the solution and future prevention Citrix have engaged leading cyber security firms to assist our internal team with its forensic investigation, and also cooperating with the FBI in connection with their investigation of the cyber criminals”, Peter Lefkowitz, Chief Privacy and Digital Risk Officer said.

Additionally, and as a precaution, we have arranged for you, at your option, to enroll in Equifax ID Patrol, a complimentary one-year credit monitoring, dark web monitoring, and identity restoration service. You have until August 31, 2019, to activate the free, Citrix added in their statement.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.

Also Read:

Most Hacked Passwords – Top 100,000 Common Passwords that Already Known to Hackers

Wipro Security Breach – Employees’ accounts Hacked Through Advanced Phishing Campaign

Docker Hub Hacked – Hackers Gained Access to 190,000 Users Accounts


Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

DrayTek Devices Vulnerability Let Attackers Arbitrary Commands Remotely

The DrayTek Gateway devices, more specifically the Vigor2960 and Vigor300B models, are susceptible to...

New Stealthy Malware Leveraging SSH Over TOR Attacking Ukrainian Military

Researchers recently discovered a malicious campaign targeting Ukrainian military personnel through fake "Army+" application...

CISA Warns of Palo Alto Networks PAN-OS Vulnerability Exploited in Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert on...

US Treasury Department Breach, Hackers Accessed Workstations

The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

US Treasury Department Breach, Hackers Accessed Workstations

The Biden administration confirmed that a Chinese state-sponsored hacking group breached the U.S. Treasury...

AT&T and Verizon Hacked – Salt Typhoon Compromised The Network For High Profiles

AT&T and Verizon Communications, two of America's largest telecommunications providers, have confirmed they were...

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a...