Cisco traces IntelBroker data leak to public DevHub portal

Organization
Cisco Systems
Exploit
Misconfiguration
Industry
Technology

On October 14, 2024, a threat actor using the alias IntelBroker advertised a large cache of Cisco material on a cybercrime forum, claiming to have obtained it on October 6. The listing described GitHub and GitLab projects, SonarQube projects, source code, hard-coded credentials, certificates, API tokens, Docker builds, AWS and Azure storage buckets, and private and public keys.

IntelBroker named a long list of organizations whose data was supposedly included, among them Microsoft, AT&T, Bank of America, National Australia Bank and Vodafone Australia, alongside Australian public bodies such as the Reserve Bank of Australia and the Australian Red Cross Blood Service. Cyber Daily, which reviewed sample data, said it had not been able to verify the claims. National Australia Bank said it was aware of the posts and had contacted Cisco for information.

Cisco opened an investigation and published a running statement the following day. It said the files had been downloaded from devhub.cisco.com, a public resource center for sharing software code and scripts, and that a configuration error had left some files publicly reachable that were never authorized for release. A limited set of CX Professional Services customers had material in the exposed files.

Cisco disabled public access to the site while it reviewed the content, later restoring it after correcting the error. The company said it remained confident there had been no breach of its systems and no exposure of credentials that would allow access to production environments. When IntelBroker released 4.45 GB of data on December 25, 2024, Cisco said the contents matched the October 14 data set.

Sources