Data Breaches

Acronis Clarifies Hack Impact Following Data Leak

Acronis said a single customer’s account was compromised after a hacker leaked gigabytes of information on a cybercrime forum.

New York, USA - 26 April 2021: Acronis logo close-up on website page, Illustrative Editorial

Swiss data protection firm Acronis has clarified that a single customer’s account has been compromised after a hacker leaked gigabytes of information allegedly stolen from the company. 

A hacker announced on a popular cybercrime forum on Thursday that they were “leaking data of a cybersecurity company called Acronis”, claiming that they hacked the company because they were bored and wanted to humiliate them. 

The hacker is the same who recently offered to sell 160 Gb of data stolen from computer giant Acer. The company immediately confirmed that one of its document servers had been hacked, but said no customer data was stored on the compromised machine.

In the case of Acronis, the cybercriminal published a 12 Gb archive file allegedly containing certificate files, command logs, system configurations and information logs, filesystem archives, scripts, and backup configuration data.

Acronis hack

Acronis offers backup, disaster recovery, antivirus, and endpoint protection management solutions. After the incident came to light, the company’s CISO, Kevin Reed, clarified in a post on LinkedIn that the leaked data appears to come entirely from a single customer’s account. 

“Based on our investigation so far, the credentials used by a single specific customer to upload diagnostic data to Acronis support have been compromised. We are working with that customer and have suspended account access as we resolve the issue. We also shared IOCs with our industry partners and work with law enforcement,” Reed said.

He added, “No other system or credential has been affected. There is no evidence of any other successful attack, nor there is any data in the leak that is not in the folder of that one customer. Our security team is obviously on high alert and the investigation continues.”

Acronis has also separately clarified that none of its products are impacted by the breach.

Related: 25k Nissan Customers Affected by Data Breach at Third-Party Software Developer

Advertisement. Scroll to continue reading.

Related: Atlassian Investigating Security Breach After Hackers Leak Data

Related: 20 Million Users Impacted by Data Breach at Instant Checkmate, TruthFinder

Related Content

Data Breaches

Acuity, the tech firm from which hackers claimed to have stolen State Department and other government data, confirms hack, but says stolen info is...

Data Breaches

A weakness in a Firebase implementation allowed researchers to gain access to names, phone numbers, email addresses, plaintext passwords, confidential messages, and more.

Vulnerabilities

ExpressVPN disables split tunneling on Windows after learning that DNS requests were not properly directed.

Government

Former CIA software engineer sentenced to 40 years in prison for biggest theft of classified information in CIA history and for possession of child...

Data Breaches

A leaked token provided unrestricted access to the entire source code on Mercedes-Benz’s GitHub Enterprise server.

Cybercrime

Naz.API credential stuffing list containing 70 million unique email addresses and old passwords found on hacking forum.

Data Breaches

Exposed credentials for an email address at an Indian Toyota insurance broker led to customer information compromise.

Uncategorized

Real Estate Wealth Network database containing real estate ownership data, including for celebrities and politicians, was found unprotected.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version