
Cisco Data Breach via Vishing Attack on Third-Party CRM
Cisco confirmed a data breach following a voice phishing (vishing) attack that tricked an employee and led to unauthorized access to a third-party cloud-based CRM system.
Key points
- Breach caused by a vishing attack targeting an employee.
- Unauthorized access gained to a third-party cloud-based CRM system.
- Stolen data includes names, email addresses, phone numbers, user IDs, and organization details.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Aug 8, 2025
- Updated
- Jun 26, 2026
- Confidence
- Medium
- Evidence
- 1 source
Structured assessment
Signal analysis
It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch phishing, executive impersonation and account-takeover exposure.
- Source type: possible insider or internal misuse
Business impact
- Impact area
- Confidentiality
- Likely asset
- User or customer data, Server or cloud data store
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?+
Cisco confirmed a data breach following a voice phishing (vishing) attack that tricked an employee and led to unauthorized access to a third-party cloud-based CRM system. The attacker stole basic profile information of users registered on Cisco.com, including names, email addresses, phone numbers, user IDs, and organization details. No sensitive data, passwords, or confidential customer information was compromised.
When was this signal reported?+
Shadow Tier lists Aug 8, 2025 as the signal date.
Which organization is connected to this signal?+
Cisco is the organization connected to this public signal.
Explore CiscoWhich attack pattern is relevant?+
This signal is connected to phishing and social-engineering intelligence based on its reported incident context.
Explore phishing and social-engineering intelligenceRelated signals
Compare shared topics, actors and incident patterns before opening the full signal.
DoorDash Confirms Data Breach After Social Engineering Attack
DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users. The breach, which occurred on October 25, was a result of a social engineering attack targeting a company employee. This allowed an unauthorized third party to gain access to DoorDash's internal systems. The compromised data varied by individual but potentially included first and last names, phone numbers, email addresses, and physical addresses of customers, Dashers (delivery drivers), and merchants across the United States, Canada, Australia, and New Zealand. DoorDash emphasized that no sensitive financial information, such as Social Security numbers, government-issued IDs, driver's license details, bank information, or payment card data, was accessed. The company's security team identified and shut down the unauthorized access shortly after its detection, launched an internal investigation, and notified law enforcement. DoorDash has also implemented multiple security enhancements, including upgraded security systems and additional employee training programs focused on social engineering awareness. While the company has stated there is no indication the data has been misused for fraud or identity theft, affected users are advised to be cautious of unsolicited communications requesting personal information. This incident marks DoorDash's third known cybersecurity incident in six years, highlighting the persistent threat of social engineering attacks.
Related context
Xsolis Data Breach Exposes 1.4 Million Patient Records Across Eight Health Systems
A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolis’s IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 — roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health — Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint — from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records — making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHS’s Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendor’s client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health system’s own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendor’s security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes
Related context
Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals
Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts. Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.
Related context
Origin Energy Discloses Data Breach Affecting 900,000 Customers
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.
Related context
South Korean Domain Registrar Gabia Hacked, Exposing 350,000 User Records
South Korean domain registrar Gabia experienced a cyberattack on Saturday, July 26, 2026, which impacted the online connectivity of approximately 100,000 registered domains. The incident led to the exposure of data belonging to 350,000 users. The compromised information included names, user IDs, passwords, and registration numbers. This breach highlights the significant risks associated with compromised credential reuse, as a large portion of the exposure originated from "Combolist sources." Additionally, active infostealer activity, linked to malware families such as LummaC2, Redline, and Rhadamanthys, was identified, further indicating a focus on credential theft impacting both clients and employees. The incident also revealed 245 compromised employee accounts, posing an infrastructure risk, and 30,782 leaked client credentials, creating regulatory liability. The timeline of related events showed an increase in client-related incidents from August 2025 through April 2026, with a peak in March 2026, and spikes in employee-related events in January, April, and May 2026. Remediation efforts should prioritize credential hygiene, multi-factor authentication enforcement, and enhanced monitoring for suspicious login activity, particularly targeting login forms and account management services. The incident was reported by the Korea Herald on Monday, July 28, 2026.
Coupang Data Breach: Authentication Failures Expose Customer Data in South Korea
South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.
Related context