Lumen Technologies discloses two separate cyberattacks in SEC filing
- Organization
- Lumen Technologies
- Exploit
- Ransomware
- Industry
- Telecommunications
Lumen Technologies, the Monroe, Louisiana communications and network services provider, told the US Securities and Exchange Commission on 27 March 2023 that it was dealing with two unrelated intrusions.
In the first, an attacker placed ransomware on a limited number of servers supporting a segmented hosting service. Lumen said the infection was degrading operations for a small number of its enterprise customers and that it was still weighing how to respond.
The second came to light through recently deployed security software. Lumen said a separate and more sophisticated intruder had reached a limited number of its internal IT systems, carried out reconnaissance, installed malware and removed a relatively limited amount of data. The company said it was still assessing whether any personally identifiable or otherwise sensitive information had been exfiltrated.
Lumen notified law enforcement, engaged outside security firms and began business continuity and restoration work. It told investors it did not believe either incident would have a material impact on its financial results. In a statement to SecurityWeek, the company said a small handful of enterprise customers had recently been affected and that it had no evidence pointing to direct customer application access. Lumen did not identify the ransomware strain, say how many customers were affected, or disclose whether it had communicated with the attackers.