Credential theft
Cisco WebEx AWS IAM User Compromise
Primary Source βIncident Details
Cisco disclosed in February 2021 that unauthorized actors had compromised AWS IAM credentials associated with the Cisco WebEx Teams video conferencing service. The attackers maintained access from approximately September 2020 through discovery in early 2021 β a dwell time of approximately five months. The incident was attributed to the use of long-lived IAM user credentials rather than role-based temporary credentials. Cisco took remediation steps including rotating all affected credentials and implementing enhanced monitoring. The extended dwell time highlighted the difficulty of detecting credential-based attacks that use legitimate access patterns.
Technical Details
- Initial Attack Vector
- Attackers compromised AWS IAM user credentials associated with Cisco WebEx's infrastructure, gaining access to Cisco's cloud environment and exfiltrating data before the intrusion was detected
- Vendor / Product
- Amazon Web Services (IAM); Cisco WebEx
Timeline
- 2020-09-24 Breach occurred
- 2021-02-10 Publicly disclosed
- 2021-02-10 Customers notified