Data Breaches

JumpCloud Says Sophisticated Nation-State Hackers Targeted Specific Customers

JumpCloud says a sophisticated nation-state threat actor breached its systems, targeting specific customers.

JumpCloud says a sophisticated nation-state threat actor breached its systems, targeting specific customers.

Directory, identity, and access management solutions provider JumpCloud has disclosed customer impact following a nation-state cyberattack.

After resetting customer API keys on July 5, the company revealed last week that the security measure was triggered as part of its response to a cyberattack perpetrated by a “sophisticated nation-state sponsored threat actor”. The threat actor or the country allegedly sponsoring it have not been named. 

The attack started on June 22 with a spear-phishing campaign that led to unauthorized access to a specific area of JumpCloud’s infrastructure.

After discovering anomalous activity on an internal orchestration system on June 27, the company reset credentials and took additional security measures.

On July 5, after discovering unusual activity “in the commands framework for a small set of customers”, the company reset all admin API keys and started notifying the impacted customers.

“At this point in time, we had evidence of customer impact and began working closely with the impacted customers to help them with additional security measures,” JumpCloud said.

The company’s investigation into the incident uncovered that the threat actor injected data into the company’s commands framework. According to JumpCloud, the attack vector has been mitigated.

“The analysis also confirmed suspicions that the attack was extremely targeted and limited to specific customers,” JumpCloud said, without providing information on the exact number of impacted customers.

Advertisement. Scroll to continue reading.

“These are sophisticated and persistent adversaries with advanced capabilities,” the company also noted.

JumpCloud notified law enforcement of the attack and published a list of indicators of compromise (IOCs) to help other organizations identify similar attacks.

“These are sophisticated and persistent adversaries with advanced capabilities. Our strongest line of defense is through information sharing and collaboration. That’s why it was important to us to share the details of this incident and help our partners to secure their own environments against this threat,” the company said.

SecurityWeek has emailed JumpCloud for additional information on the attack and will update this article if a reply arrives.

JumpCloud provides single sign-on, multi-factor authentication, and other cloud and device security solutions to more than 180,000 organizations.

Related: Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack

Related: Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Related: Microsoft Says Early June Disruptions to Outlook, Cloud Platform, Were Cyberattacks

Related Content

Cybercrime

Zscaler says its customer, production and corporate environments are not impacted after a notorious hacker offers to sell access.

Ransomware

Philadelphia-based real estate company Brandywine Realty Trust shuts down systems following a ransomware attack.

Data Breaches

University System of Georgia says Social Security numbers and bank account numbers were compromised in the May 2023 MOVEit hack.

Data Breaches

Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords. 

Data Breaches

Financial Business and Consumer Solutions (FBCS) says compromised information may include names, dates of birth, Social Security numbers, and account information.

Data Breaches

UnitedHealth confirms that personal and health information was stolen in a ransomware attack that could cost the company up to $1.6 billion.

Data Breaches

The LockBit ransomware gang leaks data allegedly stolen from government contractor Tyler Technologies.

Ransomware

United Nations Development Programme (UNDP) investigating a ransomware attack in which hackers stole sensitive data.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version