AccidentalMisconfigurationCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICCREDENTIALSLowContained
Cisco
bd_3d2551753ac82183 · schema v1 · pii pii-v1
Full breach record for Cisco →Cisco Systems, Inc. reported a data security breach to the California Attorney General regarding its Professional Careers mobile website. An independent security researcher discovered that job application data was accessible due to incorrect security settings following system maintenance. Affected data included names, addresses, emails, phone numbers, usernames, passwords, and resume text. The vulnerability existed from August 2015 to September 2015 and again from July 2016 to August 2016. Cisco corrected the settings, disabled passwords, and required password resets.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64548
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2016
- Raw hash
- cc5942f13b77044d778fe46278e47f8137c07516701e3c966ee5741a366fa33e
Reporting entity
- Name
- Cisconorm: cisco
- Domain
- cisco.com
Victim entity
- Name
- Cisconorm: cisco
- Domain
- cisco.com
Incident
- Discovered
- Aug 18, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(68 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.