Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Cisco Breach 2022: How a Synced Browser Password…
Breach analysis Incident: 24 May 2022

Cisco Breach 2022: How a Synced Browser Password and MFA Fatigue Opened Cisco’s VPN

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 10 min read
On this page

In May 2022, an attacker got into Cisco's corporate network through one employee's VPN account. According to Cisco Talos, the employee's Cisco credentials had been saved in their browser and synchronised to a personal Google account, which the attacker had taken over. A strong password was only half the problem: the attacker then ran voice phishing calls and repeated push requests until the employee accepted a multi-factor authentication prompt. Once inside, the intruder enrolled new MFA devices, reached domain controllers, dumped credential databases and used machine accounts to move laterally. Cisco says it found no impact on its products, customers or business, and no ransomware was deployed, but the Yanluowang ransomware gang later published stolen files. The Cisco breach is one of the clearest public accounts of how MFA push approval can be socially engineered.

Key takeaways

  • Cisco became aware of the compromise on 24 May 2022 and published details through Cisco Talos on 10 August 2022.
  • Initial access came from an employee's corporate credentials saved in the browser and synced to a personal Google account the attacker controlled, followed by voice phishing and MFA push fatigue to get onto the VPN.
  • After access, the attacker enrolled a series of new MFA devices, compromised Citrix servers, obtained privileged access to domain controllers and used machine accounts for privileged authentication and lateral movement.
  • Talos linked the intruder to an initial access broker with ties to UNC2447, Lapsus$ and Yanluowang. Yanluowang posted stolen files on 11 September 2022; Cisco said they matched what it had already disclosed.
  • Lessons: keep corporate credentials out of personal browser profiles, use phishing-resistant MFA, lock down MFA device enrolment and watch machine accounts after any domain compromise.

At a glance

OrganisationCisco Systems
WhenCompromise identified 24 May 2022; disclosed 10 August 2022; stolen files published 11 September 2022
AttackerAn initial access broker that Cisco Talos tied to UNC2447, Lapsus$ and Yanluowang ransomware operators; Yanluowang claimed the attack
Entry pointCisco VPN, accessed with an employee's stolen credentials after an accepted MFA push
Identities abusedOne employee's corporate account (password synced from a personal Google account, MFA approved under social engineering); newly enrolled MFA devices; domain controller credentials; machine accounts; a locally created administrator account
ImpactContents of a Box folder linked to the compromised employee and employee authentication data from Active Directory exfiltrated; no ransomware deployed; Cisco reported no business impact
CategoryHuman identity (initial access), with machine accounts abused after compromise

What happened

Cisco says it became aware of a potential compromise on 24 May 2022. It disclosed the incident on 10 August 2022, the same day Cisco Talos published a detailed technical write-up.

According to Talos, "A Cisco employee's credentials were compromised after an attacker gained control of a personal Google account where credentials saved in the victim's browser were being synchronized." The password alone was not enough, because Cisco's VPN required multi-factor authentication. Talos says the attacker "conducted a series of sophisticated voice phishing attacks under the guise of various trusted organizations attempting to convince the victim to accept multi-factor authentication (MFA) push notifications." The Register reported that callers used various accents and posed as trusted organisations. Eventually the employee accepted a push, giving the attacker VPN access as that user.

Talos says that once inside, the attacker "enrolled a series of new devices for MFA and authenticated successfully to the Cisco VPN." From there the intruder moved into the Citrix environment, compromised a series of Citrix servers and obtained privileged access to domain controllers. Talos observed attempts to dump the NTDS database with ntdsutil.exe, and The Register reported the use of tools including adfind and secretsdump. Talos also says the attacker was "leveraging machine accounts for privileged authentication and lateral movement" after reaching the credential databases.

For persistence, the intruder created a local administrator account named "z", dropped remote access tools including LogMeIn and TeamViewer, abused Windows logon accessibility features to get a SYSTEM-level command prompt, changed host firewall settings to allow RDP and cleared event logs with wevtutil.exe. Cisco says it implemented a company-wide password reset immediately after learning of the incident. After the attacker was evicted, Talos saw "continuous attempts to re-establish access" and repeated attempts to email Cisco executives.

Talos says the only successful exfiltration was the contents of a Box folder associated with the compromised employee's account and employee authentication data from Active Directory, and that the Box data was not sensitive. It found no evidence the attacker reached critical internal systems such as product development or code signing. Talos described the activity as consistent with "pre-ransomware activity", but no ransomware was deployed.

The Yanluowang ransomware gang claimed the attack. BleepingComputer reported that the gang said it stole about 2.75 GB of data in roughly 3,100 files; The Register put the figure at about 3,700 files. On 11 September 2022 the gang published the files. Cisco said "the content of these files match what we already identified and disclosed". The gang claimed to have taken 55 GB including source code, which Cisco disputed, saying it had no evidence the actor accessed product source code.

Timeline

DateEvent
Before May 2022Attacker takes over an employee's personal Google account containing synced Cisco credentials (Talos; exact date not published).
By 24 May 2022Voice phishing and MFA push requests lead to VPN access; attacker enrols new MFA devices and moves to Citrix and domain controllers.
24 May 2022Cisco becomes aware of a potential compromise and begins response, including a company-wide password reset.
Following weeksAttacker repeatedly tries to regain access and to contact Cisco executives by email.
10 August 2022Cisco discloses the incident and Talos publishes its technical analysis; the attackers share file listings with BleepingComputer.
11 September 2022Yanluowang publishes stolen files; Cisco says they match what it already disclosed.

How it happened: the identity attack path

  1. Work credentials in a personal account. The employee's Cisco password was saved in the browser and synchronised to a personal Google account. Taking over that consumer account handed the attacker a working corporate credential, outside any control Cisco had.
  2. MFA defeated by people, not technology. Push-based MFA stood between the password and the VPN. The attacker combined repeated push requests with phone calls impersonating trusted organisations until the employee approved one.
  3. Enrolling the attacker's own factors. With a session in hand, the attacker registered new MFA devices, turning one approved push into durable access that no longer depended on the victim.
  4. From one user to the directory. Through Citrix servers the attacker reached domain controllers, tried to dump NTDS and pulled authentication data from Active Directory.
  5. Machine accounts and local admins for movement and persistence. Talos says the attacker used machine accounts for privileged authentication and lateral movement, and created a local administrator account named "z" alongside remote access tools.
  6. Detection before encryption. Cisco found and evicted the intruder before any ransomware was deployed, then reset passwords company-wide.

Impact

  • Data: contents of a Box folder associated with the compromised employee (not sensitive, according to Talos) and employee authentication data from Active Directory. Yanluowang's claims of 2.75 GB, and later 55 GB, were claims by the attacker; Cisco disputed any access to product source code.
  • Business: Cisco said it did not identify any impact to its products or services, sensitive customer data, sensitive employee information, intellectual property or supply chain operations.
  • Operations: a company-wide password reset and a sustained effort to block the attacker's repeated attempts to return.
  • Afterlife of the data: in February 2025 the Kraken ransomware group posted usernames, identifiers and password hashes, and Cisco said the incident behind them "occurred back in May 2022", covered in our page on the Cisco Active Directory credentials leak.

What this means for identity security

Cisco is a human identity breach at the front door. The attacker never exploited a Cisco product vulnerability. They collected a password from a place Cisco could not see, a personal browser profile, and then talked a person into approving an MFA prompt. Talos's own recommendations focus on user education about MFA bypass, device verification before MFA enrolment and endpoint posture checks before VPN access.

Two parts of this breach map directly onto non-human identity risk. First, the machine accounts. Once the attacker held directory credentials, Talos says they used machine accounts to authenticate with privilege and move laterally. Machine and service accounts are attractive precisely because they rarely have MFA, their activity is noisy and routine, and few teams notice when one starts logging in somewhere new. After any domain compromise, those credentials need resetting and watching as carefully as human ones.

Second, the credential sat somewhere it should never have been. Browser-synced corporate passwords in personal accounts are the human version of secrets pasted into personal repositories, laptops or chat tools: the organisation loses sight of where its credentials live. Our guide to the secret sprawl challenge covers the machine side of that problem.

Recommendations

  • Move to phishing-resistant MFA for VPN and other remote access, and at minimum use number matching rather than simple approve or deny pushes. Our Workforce Identity Security Guide explains the options.
  • Control MFA device enrolment. Require strong verification before a new factor is registered, and alert when an account adds several devices in a short period.
  • Keep corporate credentials out of personal browser profiles. Use managed browsers and password managers, and block sync of work credentials to personal accounts.
  • Check device posture before VPN access, so a valid user on an unknown machine does not get a full tunnel.
  • Treat machine accounts as privileged identities. Inventory them, restrict where they can authenticate and rotate them after any directory compromise, as covered in the Privileged Access Management Guide.
  • Centralise logs off the host. The attacker cleared local event logs; centrally collected logs survive that.

Frequently asked questions

How was Cisco hacked in 2022?

An attacker took over an employee's personal Google account that held synced Cisco credentials, then used voice phishing and repeated MFA push requests until the employee approved one, giving VPN access to Cisco's corporate network.

Did Yanluowang deploy ransomware at Cisco?

No. Cisco Talos said it did not observe ransomware deployment, although the attacker's techniques were consistent with pre-ransomware activity. The Yanluowang gang later published stolen files, which Cisco said matched what it had already disclosed.

Is the Cisco 2022 breach a non-human identity breach?

The entry point was a human account and MFA fatigue. After reaching the domain, though, the attacker used machine accounts for privileged authentication and lateral movement, which is why we cover both the human and machine identity lessons.

Cisco Active Directory credentials leak · Cisco DevHub NHI breach · Uber breach · MGM Resorts breach 2023 · Human vs Non-Human Identity

How NHI Mgmt Group can help

Once attackers are past the front door, machine accounts, service accounts and stored secrets are what let them move and persist. Our NHI Foundation Level Training Course shows teams how to discover, own and protect these non-human identities alongside their workforce identity controls.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org