2024 Sisense — self-managed GitLab compromise; CISA urges credential rotation (customer tokens, S3 exposure)
Data compromised
API tokens, database and SSO integration secrets, certificates, and backups as described in Krebs/CISA advisories—exact scope customer-dependent
Technical writeup
Sisense disclosed that threat actors gained access to a self-hosted GitLab deployment and pivot material reportedly used to reach large Amazon S3 buckets, exfiltrating terabyte-scale archives described in press as holding customer connection secrets, tokens, SSL material, and related configuration. CISA issued a public alert directing all Sisense customers to rotate credentials and secrets that could reach—or authenticate to—Sisense-managed infrastructure, reflecting supply-chain style exposure rather than a single uniform “user table” count.
Root cause
Unauthorized access to vendor GitLab / cloud credential material enabling broad customer-secret exposure (per CISA and investigative reporting)
References
- https://www.cisa.gov/news-events/alerts/2024/04/11/compromise-sisense-customer-data
- https://krebsonsecurity.com/2024/04/why-cisa-is-warning-cisos-about-a-breach-at-sisense/
- https://www.sisense.com/blog/more-on-the-april-2024-security-incident/
- https://techcrunch.com/2024/04/11/cisa-government-sisense-reset-credentials-cyberattack/