Supply chain
β Supply Chain
VAG, Ericsson, Leica, MAN, Toshiba, UniCredit, and British Telecom (BT) Third-Party Breach (May 2019)
Primary Source βIncident Details
German IT Firm CITYCOMP Data Breach Directly Affected Major Companies. Threat actors disclosed lots of financial data belonging to big firms online. The hacker gathered this data from German IT company CITYCOMP that provides services to numerous major organizations. These records from the CITYCOMP data. As disclosed by the firm itself, the German IT company CITYCOMP suffered a data breach following a failed ransom demand. The incident has affected several big names from the industry since the victim firm provided services to them. The company has stated the details of the CITYCOMP data breach in its official statement . As revealed, the firm suffered the cyber attack in April 2019. The unidentified attacker blackmailed the firm to publish the stolen data should the company not comply with its demand for ransom. Since the firm did not accept his demands, the attacker published the breached data. Third-party company: CITYCOMP.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- CITYCOMP
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2019-05-01 Breach occurred
- 2019-05-03 Publicly disclosed