Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Cisco data breach exploited employee via vishing call

A cybercriminal exploited a Cisco employee using a vishing scheme, gaining access to a third-party CRM and extracting Cisco.com user profile data including names, emails, and phone numbers.

byKerem Gülen
August 5, 2025
in Cybersecurity, News
Home News Cybersecurity

Cisco has confirmed a data breach affecting users of its public website, Cisco.com, after a cybercriminal exploited a company representative through a voice phishing attack. The breach, discovered on July 24, targeted a third-party cloud-based CRM system used by the company to manage user profiles and engagement.

What happened?

According to Cisco’s official disclosure, the attacker tricked an employee via a social engineering technique known as “vishing” — a phone-based phishing scheme. This deception granted the actor temporary access to one instance of a cloud-based customer relationship management (CRM) platform. The breach allowed the actor to extract a subset of user profile information from Cisco.com’s registration database.

What data was accessed?

The stolen data includes:

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

  • Full name
  • Organization name
  • Physical address
  • Cisco-assigned user ID
  • Email address
  • Phone number
  • Account metadata (e.g., creation date)

Cisco emphasized that no passwords, sensitive data, or confidential enterprise information were compromised. The company also stated that the breach had no impact on its products or services.

Was Salesforce involved?

While Cisco did not name the specific CRM vendor affected, industry observers suspect the attack may be linked to a broader campaign targeting Salesforce customers. Cisco is a known Salesforce client, and other recent breaches — including incidents at Qantas, Tiffany & Co., and Allianz Life — have followed a similar pattern involving vishing and third-party system exploitation. Cisco has not confirmed whether its Salesforce instance was the system involved.

How did Cisco respond?

Immediately after identifying the breach, Cisco revoked the attacker’s access to the CRM system and launched a full investigation. The company has notified users as required by data protection laws and is cooperating with regulatory authorities. To prevent future incidents, Cisco is implementing additional security measures, including employee training on social engineering threats and enhanced access controls across its systems.

User impact and next steps

While the full number of affected users has not been disclosed, this incident underscores the risks of phishing-based attacks even in large enterprise environments. Users with Cisco.com accounts are advised to remain alert for suspicious communications and verify the authenticity of any Cisco-related outreach. Although passwords were not stolen, good practice suggests reviewing account security settings and enabling multi-factor authentication where available.

Historical context

This Cisco data breach follows a separate October 2024 incident in which threat actors exploited a misconfigured DevHub portal to access non-public customer files. That breach was later confirmed to involve downloads of documents tied to Cisco’s CX Professional Services division. Taken together, these events highlight the persistent challenge of securing third-party systems and publicly accessible developer tools.

Why this matters

For users and IT teams alike, the Cisco data breach is a reminder of how human vulnerabilities — not just technical flaws — can open the door to cyberattacks. With the rise of sophisticated vishing tactics, even well-trained employees can be deceived. Organizations that rely on third-party platforms for customer engagement must enforce robust access governance and incident response plans tailored for social engineering risks.

Tags: CiscoData BreachFeatured

Related Posts

Zoom announces AI Companion 3.0 at Zoomtopia

Zoom announces AI Companion 3.0 at Zoomtopia

September 19, 2025
Google Cloud adds Lovable and Windsurf as AI coding customers

Google Cloud adds Lovable and Windsurf as AI coding customers

September 19, 2025
Radware tricks ChatGPT’s Deep Research into Gmail data leak

Radware tricks ChatGPT’s Deep Research into Gmail data leak

September 19, 2025
Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

September 19, 2025
Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

September 19, 2025
DeepSeek releases R1 model trained for 4,000 on 512 H800 GPUs

DeepSeek releases R1 model trained for $294,000 on 512 H800 GPUs

September 19, 2025

LATEST NEWS

Zoom announces AI Companion 3.0 at Zoomtopia

Google Cloud adds Lovable and Windsurf as AI coding customers

Radware tricks ChatGPT’s Deep Research into Gmail data leak

Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

DeepSeek releases R1 model trained for $294,000 on 512 H800 GPUs

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.