Cybercrime

Ad Tech Company Optimizely Targeted in Cyberattack

The company says the attackers accessed internal business systems such as Zendesk and Salesforce.

Advertising firm cyberattack

Ad tech firm Optimizely has confirmed that threat actors accessed certain internal business systems through a sophisticated voice phishing (vishing) attack.

The incident, the company told SecurityWeek, was immediately contained, the affected systems were secured, and the unauthorized access was terminated.

“The threat actor gained access to Optimizely’s systems through a sophisticated voice-phishing attack, but was unable to escalate privileges, install software, or create any backdoors in the Optimizely environment,” the company said.

Optimizely says it has no evidence of any sensitive customer data or personal information being compromised in the attack, but has proactively notified its customers of the incident.

The company said the incident did not disrupt its operations and confirmed that the attackers were able to access business contact information.

“The incident was confined to certain internal business systems including Zendesk, records in our Salesforce CRM, and a limited set of internal documents used for back-office operations,” the company said.

Advertisement. Scroll to continue reading.

Optimizely has notified law enforcement of the attack and has engaged third-party cybersecurity experts and legal counsel to aid with the investigation.

“We are prioritizing transparency with our customers and partners; we have informed them of the incident and its scope and are continuing to provide updates and individual guidance to them directly,” the ad tech firm told SecurityWeek.

Optimizely did not name the threat actor behind the attack, but its description of the incident suggests that the infamous ShinyHunters extortion group might have been responsible for it.

Based in New York, Optimizely provides a digital experience platform enabling organizations to improve their websites and digital content.

It operates 21 offices worldwide, has nearly 1,500 employees, and provides services to more than 10,000 businesses, including H&M, PayPal, Toyota, Vodafone, and Zoom.

Related: US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

Related: PayPal Data Breach Led to Fraudulent Transactions

Related: Nearly 1 Million User Records Compromised in Figure Data Breach

Related: Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version