Desk live·
ForensicPost
Breaches/Identity/File 22-0524

Cisco Breach Began With Corporate Credentials Synced to a Personal Google Account

A Cisco employee’s corporate credentials were saved in Chrome and synced to their personal Google account. The attackers took that account, then called the employee, impersonated support, and pushed notifications until one was approved.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCisco
ActorYanluowang
D. Kennedy11 min readConfidence: high2 sources reviewed

Cisco disclosed an intrusion on its corporate network in late May 2022, later associated with the Yanluowang operation. Cisco Talos described initial access as the compromise of an employee’s personal Google account, into which corporate credentials had synchronised because the employee had saved them in Chrome with password sync enabled.

Holding the credentials, the attackers ran voice phishing calls impersonating trusted support organisations while sending repeated multi-factor push notifications. One was accepted, giving VPN access in the employee’s context, after which the activity moved laterally toward Citrix servers and domain controllers. The group claimed around 2.75GB across roughly 3,100 files.

The Third Way A Second Factor Fails

This corpus now holds all three from the same year. At 22-0915 a contractor approved a push under social pressure. At 22-1101 a hardware key emitted a typed code that was relayed. Here a push was approved after a phone call made the prompt look expected.

None of the three involved a broken factor. Each involved a factor doing precisely what it was built to do, in a moment engineered so that doing so was the wrong outcome. The distinguishing property at 22-0808 was origin binding, which removes the user’s judgement from the transaction; everything else on this list asks a person a question at a time chosen by the attacker.

Sync Is A Feature, And It Crossed The Boundary

No policy was broken by the browser. Password sync exists so that a person’s credentials follow them between devices, and it did that. The consequence is that a corporate secret came to rest in a personal account governed by nobody’s security programme.

We filed the same boundary problem at 22-1222, where the route into a password manager ran through an engineer’s home computer, and at 26-0703. An organisation’s perimeter includes every account its staff can sync to, which is not a set the organisation knows.

Publishing The Method

Cisco’s threat intelligence group published a detailed account of the intrusion, including the credential path and the social engineering. That is unusual, and it is the reason this file can state a route at all.

We have recorded at 26-0802 that a quarter of its files establish no entry route, because most organisations describe an incident without describing how it started. A vendor writing up its own compromise in technical detail is the exception, and the desk records it as one.

How we reported this

Compiled from Cisco Talos’s published account and contemporaneous reporting of it, listed below. The ~2.75GB / ~3,100 files figure is the extortion group’s claim about its own haul and is carried as a claim, not a count. Cisco stated no ransomware was deployed and that it did not identify impact to its products or services; that is recorded as the company’s position. No individual is named — the employee is a victim of the attack. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Cisco Talos shares insights related to recent cyber attack on CiscoCisco Talos
  2. Cisco hacked by Yanluowang ransomware gang, 2.8GB allegedly stolenBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary