Cisco confirms attackers stole data, shuts down access to compromised DevHub environment
The tech giant insists that no sensitive customer information has been compromised
Cisco has closed public access to one of its third-party developer environments after threat actors successfully stole data from a public-facing DevHub environment.
On 14 October, the prominent threat actor IntelBroker posted on BreachForums that they compromised data including source code, hard-coded credentials, certificates, API tokens, private and public keys, AWS private buckets, Docker builds, and Azure storage buckets as well as GitHub and GitLab projects.
The listing also claimed to have access to confidential documents and premium products belonging to Cisco.
IntelBroker listed a number of companies that had their production source code taken during the attack, including Verizon, AT&T, Bank of America, Barclays, British Telecoms, Microsoft, Vodafone, Chevron and Charter Communications.
On 15 October, Cisco announced it was investigating reports that a threat actor had claimed to have gained access to data belonging to Cisco and its customers.
The firm updated this advisory on 18 October, confirming that the data the unauthorized actors gained access to was hosted in a public-facing DevHub environment used as a resource center for community support.
“At this stage in our investigation, we have determined that a small number of files that were not authorized for public download may have been published,” the statement added.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“As of now, we have not observed any confidential information such as sensitive PII or financial data to be included but continue to investigate to confirm.”
Evidence points towards compromised third-party as Cisco maintains none of its systems were breached
IntelBroker, a Russia-based Serbian hacker, has been active in the black hat community since October 2022, and came to prominence after their attack on US food delivery service Weee! In 2023.
Since then IntelBroker has targeted major organizations including Europol, Pandabuy, Apple, and AMD, although in these most recent cases the victims have all queried the scope of the breach, claiming the threat actor’s access was limited to a small amount of data.
IntelBroker took to X on 16 October to goad Cisco, claiming they still had access to the developer environment.
RELATED WHITEPAPER
The post noted that Cisco had previously attempted to disable its access but had used hard-coded credentials on an SSH server IntelBroker identified within the exfiltrated data.
Two days later, Cisco announced it had disabled public access to the site while it continued its investigation, which IntelBroker confirmed shortly afterward on X, stating that the company had “finally revoked all our access. Closed our Docker, Maven hub[s] and SSH access.”
In its latest update, Cisco maintains it is confident there was no breach to its systems.
ITPro has approached Cisco for clarification on this matter but has not received a response.

Solomon Klappholz is a former staff writer for ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing, which led to him developing a particular interest in cybersecurity, IT regulation, industrial infrastructure applications, and machine learning.
-
Modernizing enterprise infrastructure: business’ growing need for powerful infrastructure in the face of AI and HPC workloadsJane McCallion speaks with AHEAD’s Chris Tucker (EVP of AHEAD Foundry) and Paul Allen (EVP of EMEA Sales) about the company’s global expansion, the operational power of their Foundry facilities, and how tools like Hatch are revolutionizing supply chain transparency for modern high-performance workloads
-
Sovereignty is the channel’s next trust testIndustry Insights Data sovereignty has become a key channel priority
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
CISOs are keen on agentic AI, but they’re not going all-in yetNews Many security leaders face acute talent shortages and are looking to upskill workers
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
Cisco says Chinese hackers are exploiting an unpatched AsyncOS zero-day flaw – here's what we know so farNews The zero-day vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager appliances – here's what we know so far.
-
Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network AcademyNews The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
-
Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warningsNews Cisco customers are urged to upgrade and secure systems immediately
-
Cisco eyes network security gains for agentic AINews New network security updates aim to secure AI agents across enterprises