Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

April 17, 2024 Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one of its third-party telephony service providers. Cisco has issued an advisory to customers, alerting them of potential follow-up phishing attempts leveraging the breach.

The incident, which occurred on April 1, involved unauthorized access by threat actors using stolen employee credentials to download SMS logs from the provider’s systems. These logs contained metadata such as phone numbers, carriers, and message times for messages sent in March 2024, though no content from the messages was exposed.

Upon discovery, Cisco Duo informed its customers and advised them to caution any individuals whose data may have been compromised. The company stressed the importance of vigilance against subsequent phishing attacks that may use the stolen information.

This breach underscores a growing pattern of attacks targeting identity security providers. Experts, like Jeff Margolies of Saviynt, point to historical precedents, including incidents involving Okta and Microsoft, as well as the RSA SecurID Token attack in 2011.

The breach highlights the vulnerability within the supply chain of identity security services and the importance of stringent security measures. Margolies emphasizes the need for companies to understand their reliance on such third-party providers and to have robust mitigating controls in place.

In light of the breach, organizations are urged to assess the impact on their cybersecurity posture and implement additional controls to detect and respond to any incidents involving their identity security providers.

The incident with Cisco Duo is a stark reminder of the importance of cyber resilience in an increasingly interconnected digital ecosystem, where the security of one provider can have cascading effects on numerous organizations and users.

 

Top Stories

Related Articles

January 21, 2026 A new Ottawa-based defence startup founded last summer by former Anduril executive Eliot Pence has raised $21 more...

January 21, 2026 After years of rapid growth fueled by infrastructure spending and experimental use cases, OpenAI says 2026 will more...

January 21, 2026 OpenAI is pushing deeper into enterprise software as AI agents move from experimentation into day-to-day business operations. more...

January 21, 2026 CGI announced an expanded global alliance with Google Cloud this week. According to the Montreal-based IT consultant more...

Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com
Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn