Supply chain β›“ Supply Chain

Cognizant's clients Third-Party Breach (April 2020)

πŸ“… 2020-04-01 🏒 Cognizant
Primary Source β†—

Incident Details

IT services giant Cognizant suffers Maze Ransomware cyber attack. Information technologies services giant Cognizant suffered a cyber attack Friday night allegedly by the operators of the Maze Ransomware, BleepingComputer has learned. Cognizant is one of the largest IT managed services company in the world with close to 300,000 employees and over $15 billion in revenue. As part of its operations, Cognizant remotely manages its clients through end-point clients, or agents, that are installed on customer’s workstations to push out patches, software updates, and perform remote support services. Third-party company: Cognizant.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Cognizant
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2020-04-01 Breach occurred
  2. 2020-04-18 Publicly disclosed