Description

Cisco Duo issued a data breach notification regarding a breach involving one of its telephony suppliers, which compromised multifactor authentication (MFA) messages sent to customers via SMS and VOIP. The breach occurred on April 1, 2024, when threat actors used an employee's credentials obtained through a phishing attack to access and download a set of MFA SMS message logs belonging to customers' Duo accounts. The message logs contained phone numbers, phone carriers, countries, states, and metadata such as date and time of messages, but not the message content. Upon discovering the breach, the provider invalidated the compromised credentials, initiated an investigation, and implemented mitigation measures. These measures included additional training for employees to enhance social engineering awareness and technical measures to prevent similar incidents in the future. Affected users were advised to stay vigilant and report any suspicious activities promptly.