Ransomware
Cognizant / BleepingComputer / SC Magazine
Primary Source βIncident Details
Maze ransomware group attacked Cognizant, a Fortune 500 IT managed services provider with ~300,000 employees, on April 18 2020. The attack disrupted services for clients across multiple industries. Cognizant notified clients on April 20 with indicators of compromise including Maze-associated IPs and malware hashes. The incident caused $50Mβ$70M in losses in Q2 2020 per Cognizant’s own financial disclosures, primarily from lost revenue and remediation costs. Client data may have been exposed given Maze’s double-extortion model (exfiltrate then encrypt), but Cognizant did not confirm specific data theft. The incident highlighted supply-chain risk from IT service provider compromises.
Technical Details
- Initial Attack Vector
- CWE-506: Embedded Malicious Code (Maze ransomware; initial access vector not publicly confirmed, likely phishing or exploitation of exposed services)
- Malware Family
- Maze
Timeline
- 2020-04-18 Breach occurred
- 2020-04-20 Publicly disclosed
- 2020-04-20 Customers notified