Supply chain
β Supply Chain
Cisco Third-Party Breach (August 2025)
Primary Source βIncident Details
Cisco discloses data breach impacting Cisco.com user accounts. Cisco has disclosed that cybercriminals stole the basic profile information of users registered on Cisco.com following a voice phishing (vishing) attack that targeted a company representative. After becoming aware of the incident on July 24th, the networking equipment giant discovered that the attacker tricked an employee and gained access to a third-party cloud-based Customer Relationship Management (CRM) system used by Cisco. This allowed the threat actor to steal the personal and user information of individuals with Cisco.com user accounts, including names, organization names, addresses, Cisco-assigned user IDs, email addresses, phone numbers, and account metadata such as creation dates. Third-party company: Salesforce.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Salesforce
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-08-01 Breach occurred
- 2025-08-05 Publicly disclosed