Hacker IntelBroker leaked 2.9 GB of data allegedly stolen from Cisco's DevHub.

According to the hacker's own post on the dark web, this leak is part of a wider breach involving approximately 4.5 TB of data.
IntelBroker claims that Cisco's public-facing DevHub portal was exposed online, without proper security measures.
See also: Will Cisco acquire threat detection company SnapAttack?
He also said that not only he had access, but also his associates, “@zjj” and “@EnergyWeaponUser”. The hackers allegedly gained access to sensitive resources by exploiting an exposed API token. The stolen data includes:
- Source code from GitHub, GitLab and SonarQube projects.
- Hardcoded credentials, certificates and API tokens.
- Confidential Cisco documents, Jira tickets, and Docker builds.
- AWS and Azure storage buckets.
- Private and public encryption keys, SSL certificates and high-quality Cisco products.
Hacker IntelBroker first reported the breach in October 2024, via a post on the hacking forum BreachForums. To validate his claims and attract buyers for the rest of the data, he made this partial leak that contained files related to Cisco IOS XE & XR, Cisco ISE, Cisco Umbrella, Cisco Webex , and other technologies.
What's worrying is that the breach extends beyond Cisco's internal operations, with hacker IntelBroker claiming that data linked to companies including Verizon, AT&T, Microsoft, Bank of America, Barclays, Vodafone, and Chevron have also been compromised.
Cisco's response
Cisco has acknowledged the incident, but maintains that its core systems were not compromised. The company attributes the leak to a misconfigured DevHub environment designed to give developers access to resources such as software code and APIs.
As a precautionary measure, Cisco has disabled public access to the DevHub while it continues its investigation.
See also: Bootloader vulnerability affects over 100 Cisco Switches
In a statement, Cisco stressed that no personally identifiable information (PII) or financial data has been identified among the exposed files so far. The company has hired law enforcement and cybersecurity experts to further assess the situation.
This breach highlights ongoing vulnerabilities in the security of developer environments. While Cisco claims its core infrastructure remains intact, the exposure of source code and credentials could have far-reaching implications for its customers and partners.

What security measures can prevent data theft?
The first and most basic security measure is staff training. Employees need to be aware of the risks and tactics used by hackers, such as phishing, and know how to react to them.
It is also important to have a strong virus and malware protection system. This includes regularly updating your security software and installing the latest updates and patches.
See also: Cisco warns of attacks exploiting ASA vulnerability
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using multi-factor authentication is another measure that can help protect data. This means that the user must provide two or more forms of proof to prove their identity.
Additionally, regularly backing up data is vital. This ensures that even if data is stolen or lost, it can be recovered.
Finally, using encryption can provide additional protection. Encryption converts data into a code that can only be decrypted with a special key.
Source: cybersecuritynews.com
