HomeSecurityCitrix: "Our customer data was leaked after a third-party breach"

Citrix: “Our customer data was leaked after a third-party breach”

Citrix has released an official statement denying that its network was breached by a hacker who claims to have stolen the company’s customer information. The hacker is now selling what he claims is a database containing information on 2,000,000 Citrix customers on the dark webfor 2.15 bitcoins, or about $19,700. Citrix CISO Fermin J. Serna said that claims that the company’s data was put up for sale on the dark web after the company was successfully breached are untrue. He added that the hacker compromised a third-party network. Serna noted that a report was released on the dark web about a hacker’s claims that he was able to breach Citrix’s network and extract data. The hacker also reported attempts to escalate privileges to launch a ransomware attack.


However, as Citrix discovered during the investigation of these claims, the company found no indication of a breach of its network, but discovered that the hacker is stealing data from the compromised third‑party network.

data-breach

Serna also noted that the third party was notified by the company and worked with it, taking immediate action to isolate any Citrix-related data it may have from the Internet . Once this action was completed, the threat intelligence report author reported that the hacker's unauthorized access .


Citrix also stressed that no customer credentials were stolen. It explained that the third party whose systems were compromised in the Citrix data theft has now launched its own investigation and is taking remediation measures, keeping the company informed of any findings. Serna clarified that the third party breach did not involve a breach of Citrix’s network or the theft credentials . The breach of the third party’s network does not affect Citrix’s network or expose the company to a ransomware attack. This third party does not have Citrix source code , highly sensitive and confidential information, passwords or other credential information. The third party only has contact information that is not as sensitive and confidential data.

hacker

This is not the first time Citrix data has been stolen following a breach, as the company was notified by the FBI in March 2019 that hackers were able to gain and maintain access to its networks between October 13, 2018, and March 8, 2019, through password spraying. During this time, the hackers were able to access sensitive personal information of both current and former employees of the company, including names, social security numbers, and financial information. In May 2019, a former Citrix employee filed a complaint against the company, alleging damages he suffered following security .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS