Supply chain β›“ Supply Chain

VAG, Ericsson, Leica, MAN, Toshiba, UniCredit, and British Telecom (BT) Third-Party Breach (May 2019)

πŸ“… 2019-05-01 🏒 CITYCOMP
Primary Source β†—

Incident Details

German IT Firm CITYCOMP Data Breach Directly Affected Major Companies. Threat actors disclosed lots of financial data belonging to big firms online. The hacker gathered this data from German IT company CITYCOMP that provides services to numerous major organizations. These records from the CITYCOMP data. As disclosed by the firm itself, the German IT company CITYCOMP suffered a data breach following a failed ransom demand. The incident has affected several big names from the industry since the victim firm provided services to them. The company has stated the details of the CITYCOMP data breach in its official statement . As revealed, the firm suffered the cyber attack in April 2019. The unidentified attacker blackmailed the firm to publish the stolen data should the company not comply with its demand for ransom. Since the firm did not accept his demands, the attacker published the breached data. Third-party company: CITYCOMP.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
CITYCOMP
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-05-01 Breach occurred
  2. 2019-05-03 Publicly disclosed