2022 Cisco — Yanluowang affiliate gained VPN access via vishing + MFA fatigue; Box-synced folders exfiltrated (May–Aug)
Data compromised
Mixed administrative/engineering-support documents per Cisco’s classification—no confirmed customer database dump
Technical writeup
Between late May and August 2022, Cisco confirmed an intrusion on its corporate (non-product) network tied to Yanluowang extortion operators. Cisco Talos summarized that attackers started from a compromised employee personal Google account with password-manager sync, escalated through voice phishing and MFA fatigue, reached Citrix and domain controllers, and exfiltrated non-sensitive material Cisco associated with a Box share before eviction attempts continued for weeks. BleepingComputer published Cisco’s spokesperson framing: no customer PII, no sensitive IP in the stolen set, yet ~2.8 GB / ~3,100 files appeared on the gang’s leak blog—underscoring insider-risk lessons for any `cisco-systems` directory page mirroring the master Cisco corporate narrative.
Root cause
Credential takeover on personal identity store + social-engineered MFA approval + insufficient separation between consumer password hygiene and corporate VPN trust