Credential theft

Cisco WebEx AWS IAM User Compromise

πŸ“… 2020-09-24 🏒 Amazon Web Services (IAM); Cisco WebEx
Primary Source β†—

Incident Details

Cisco disclosed in February 2021 that unauthorized actors had compromised AWS IAM credentials associated with the Cisco WebEx Teams video conferencing service. The attackers maintained access from approximately September 2020 through discovery in early 2021 β€” a dwell time of approximately five months. The incident was attributed to the use of long-lived IAM user credentials rather than role-based temporary credentials. Cisco took remediation steps including rotating all affected credentials and implementing enhanced monitoring. The extended dwell time highlighted the difficulty of detecting credential-based attacks that use legitimate access patterns.

Technical Details

Initial Attack Vector
Attackers compromised AWS IAM user credentials associated with Cisco WebEx's infrastructure, gaining access to Cisco's cloud environment and exfiltrating data before the intrusion was detected
Vendor / Product
Amazon Web Services (IAM); Cisco WebEx

Timeline

  1. 2020-09-24 Breach occurred
  2. 2021-02-10 Publicly disclosed
  3. 2021-02-10 Customers notified