Skip to main content

Company intelligence

Cisco cybersecurity incidents and threat signals

cisco.com

Cisco logo

This company page brings together public reporting currently associated with Cisco. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

4

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 1, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Cisco. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Cisco

Cisco logoUse of stolen credentials or exploit
Medium

Cisco suffers cyberattack, source code and AWS keys stolen

Cisco's internal development environment was breached using stolen credentials, leading to the theft of source code, exposure of AWS keys, and unauthorized access to internal systems and customer-related repositories. The incident, disclosed on April 3, 2026, is linked to the Trivy supply chain attack and involved a malicious GitHub Action plugin used to extract credentials and data from build systems.

Cisco
Cisco logo
Medium

Cisco source code stolen in Trivy-linked dev environment breach

Cisco suffered a cyberattack where threat actors used stolen credentials from a recent Trivy supply chain attack to breach its internal development environment. Attackers stole multiple AWS keys, cloned over 300 GitHub repositories, and accessed source code belonging to Cisco and its customers, including those related to AI Assistants, AI Defense, and unreleased products.

Cisco
Cisco logoPhishing
Medium

Cisco Data Breach via Vishing Attack on Third-Party CRM

Cisco confirmed a data breach following a voice phishing (vishing) attack that tricked an employee and led to unauthorized access to a third-party cloud-based CRM system. The attacker stole basic profile information of users registered on Cisco.com, including names, email addresses, phone numbers, user IDs, and organization details. No sensitive data, passwords, or confidential customer information was compromised.

Cisco
Cisco logo
High

Cisco DevHub Data Leaked by Hacker IntelBroker

A hacker known as "IntelBroker" leaked 2.9 gigabytes of files from Cisco's DevHub platform onto BreachForums on December 18, 2024. The leaked data reportedly included source code, certificates, and internal documentation tied to Cisco products. Cisco confirmed the authenticity of the data, stating it originated from a public-facing DevHub environment due to a configuration error, not a breach of internal systems.

Cisco

FAQ

Questions about Cisco cybersecurity reporting

What does the Cisco page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Cisco.

Does every mention of Cisco appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.