CISA warned Sisense customers to reset credentials after vendor breach
- Organization
- Sisense
- Exploit
- Hacking
- Industry
- Business Analytics Software
Sisense, a business analytics vendor whose software connects to customers' own databases and cloud services, told clients on April 10, 2024 that company information had been found on a restricted access server. Chief information security officer Sangram Dash urged customers to rotate the credentials they used with the platform.
The following day the US Cybersecurity and Infrastructure Security Agency issued a public alert naming a private company, an unusual step. It told Sisense customers to reset any credentials and secrets that had been exposed to or used to access Sisense services, and to report suspicious activity. CISA said it was working with private sector partners on the response and was particularly concerned about affected critical infrastructure organisations.
KrebsOnSecurity, which broke the story, reported that the attackers had reached the company's self-managed GitLab repository, found a credential there that opened Amazon S3 storage buckets, and copied several terabytes of customer data. That material reportedly included millions of access tokens, email account passwords and SSL certificates belonging to customers in financial services, telecommunications, healthcare and higher education.
Sisense told customers to change passwords, reset API tokens, update single sign-on secrets and refresh Active Directory credentials. The company declined to comment publicly beyond the advisory it sent clients. Its customer list includes Air Canada, PagerDuty, Philips Healthcare, Skullcandy and Verizon.