Software company Citrix recently confirmed that it had been hacked by an international cybercriminal group. The hackers managed to gain access to the company's network and steal sensitive information related to both past and current employees.
The hackers had access to the network for approximately 5 months and investigations conclude that they are probably of Iranian origin.
The criminals managed to steal some documents related to the company. The positive aspect is that the products and services were not affected.
On March 6, the FBI discovered the attack and notified Citrix, which immediately proceeded with system protection procedures and assigned a company to investigate the case.
Although the attack has been known since March, Citrix is now revealing more information.
This week, the company addressed the California Attorney General's Office, reported the data leak and stated, among other things, that hackers had access to its network for approximately 5 months, from October 13, 2018 to March 8, 2019.
According to what Citrix disclosed, the hackers stole company files that included employee data such as names, social security numbers, and financial information.
The exact number of people affected by the data breach is unknown, however, California Civil Code 1798.82 (a) requires companies to report data breaches to the state Attorney General if more than 500 state residents are affected.
Citrix has taken care to inform all people affected by the attack and is compensating them by offering them free monitoring and protection services.
The company believes that hackers managed to penetrate its network using a technique called "password spraying," which exploits weak passwords. Essentially, they tried common passwords and managed to gain access to Citrix's internal network.
