4
Published signals
currently linked to this company
Company intelligence
cisco.com
This company page brings together public reporting currently associated with Cisco. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
4
currently linked to this company
0
recent published signals
0
recent published signals
1
confidence classifications
July 1, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Cisco. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
Cisco's internal development environment was breached using stolen credentials, leading to the theft of source code, exposure of AWS keys, and unauthorized access to internal systems and customer-related repositories. The incident, disclosed on April 3, 2026, is linked to the Trivy supply chain attack and involved a malicious GitHub Action plugin used to extract credentials and data from build systems.
Cisco suffered a cyberattack where threat actors used stolen credentials from a recent Trivy supply chain attack to breach its internal development environment. Attackers stole multiple AWS keys, cloned over 300 GitHub repositories, and accessed source code belonging to Cisco and its customers, including those related to AI Assistants, AI Defense, and unreleased products.
Cisco confirmed a data breach following a voice phishing (vishing) attack that tricked an employee and led to unauthorized access to a third-party cloud-based CRM system. The attacker stole basic profile information of users registered on Cisco.com, including names, email addresses, phone numbers, user IDs, and organization details. No sensitive data, passwords, or confidential customer information was compromised.
A hacker known as "IntelBroker" leaked 2.9 gigabytes of files from Cisco's DevHub platform onto BreachForums on December 18, 2024. The leaked data reportedly included source code, certificates, and internal documentation tied to Cisco products. Cisco confirmed the authenticity of the data, stating it originated from a public-facing DevHub environment due to a configuration error, not a breach of internal systems.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Cisco.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.