2026 Cisco — Trivy supply-chain CI/CD breach; 300+ GitHub repos / source code stolen (trade press)
Data compromised
Per trade reporting: 300+ private GitHub repositories cloned (AI Assistants, AI Defense, unreleased products); AWS keys used in unauthorized cloud activity; portions allegedly tied to customer repos (banks, BPOs, US agencies). No attested individual PII count — recordsAffected 0. Distinct from ShinyHunters Salesforce extortion tracked separately as cisco2026.
Technical writeup
Trade-press verified development-environment compromise — reported March 31, 2026 (BleepingComputer; SANS ISC Update 007). Threat actors leveraged credentials stolen via the TeamPCP-linked Trivy supply-chain attack to breach Cisco's internal build and development environment through a malicious GitHub Action plugin. Sources described containment by Cisco CSIRT/EOC teams, isolation and reimaging of affected systems, and wide-scale credential rotation after AWS keys were stolen and used in unauthorized activity. Reporting cites 300+ private GitHub repositories cloned, including AI product source code and some customer repositories. Cisco had not issued a standalone public customer advisory addressing repository scope in sources reviewed at August 2026 re-indexing; social posts referencing "Cisco ISE" appear to conflate this dev-environment/source-code theft with ISE product CVE advisories rather than a confirmed ISE-specific data breach. BreachHistory indexes recordsAffected 0 (no attested person count). Related ShinyHunters Salesforce extortion is cataloged separately.
Root cause
TeamPCP-linked Trivy GitHub Actions supply-chain compromise (CVE-2026-33634) enabled theft of CI/CD credentials; malicious GitHub Action plugin used to access Cisco build/dev environment per BleepingComputer and SANS ISC reporting