Everbridge told customers attackers reached corporate files after employee phishing
- Organization
- Everbridge
- Exploit
- Phishing
- Industry
- Software
Everbridge, a Massachusetts based provider of critical event management and mass notification software, notified customers in late May 2024 that an unauthorized party had accessed files on its corporate network.
The company detected the intruder on May 21, 2024. According to BleepingComputer, the attacker used information gathered in an earlier phishing campaign against Everbridge employees to get into corporate systems. The notification, quoted by the law firm Strauss Borrelli, said the party had accessed a limited number of files containing business related data. Those files included contact information for administrator accounts and for a limited number of other users, records of which Everbridge services a customer subscribed to, and the access methods each account had enabled.
Everbridge said there was no evidence of a ransomware attack and that it had notified law enforcement. It brought in incident response firms Mandiant and Stroz Friedberg to assess the severity and impact. Account administrators were sent guidance on identifying phishing attempts, and the company said multi-factor authentication would be force enabled across all accounts by June 3, 2024.
Everbridge reported more than 6,500 customers worldwide, including government and military users. It did not publish a count of affected individuals, and the notification described business data rather than the contents of the notification platform itself.