Major Data Breach At Cisco: Intel Broker Steals 4.5 TB Of Value Data

00:00 / 00:00 Game-Changing SOC Trends In 2026: AI, SOAR & XDR Shifts

The hacker group “Intel Broker” has successfully breached Cisco’s network, allegedly claiming to have exfiltrated approximately 4.5TB of sensitive data tied to various Cisco products. The breach reportedly occurred after Cisco inadvertently left its DevHub instance exposed, granting unauthorized access to critical systems.

Threat actors identified as “@zjj,” “@IntelBroker,” and “@EnergyWeaponUser” are said to have exploited this vulnerability, downloading sensitive files and sighting poor security at major institutions. IntelBroker has since claimed responsibility for the breach and the hackers are alleged to offer the data for sale on the dark web.

The exposed data includes proprietary Cisco products such as

Cisco C9800-SW-iosxe-wlc.16.11.01,

Cisco IOS XE & XR,

Cisco Identity Services Engine (ISE),

Cisco Secure Access Service Edge (SASE),

Cisco Umbrella, and

Cisco Webex.

Hackers have shared some files with the cybersecurity community to validate their claims and attract buyers for a purported “full version” of the stolen data.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

If the breach is confirmed, it could lead to serious implications for Cisco’s business. Proprietary software and platforms like Webex and Umbrella may face exploitation risks, while organizations relying on these products could encounter vulnerabilities. Cybersecurity experts are urging users of Cisco technologies to remain vigilant and monitor for security updates or patches. Cisco has not yet commented publicly on the breach, leaving the industry closely monitoring its response and future security measures.

When it comes to cybersecurity, one shouldn’t blink at the possibility of a hack. Targeted attacks such as these not only affect the organization itself but also its clients in extension. There are multiple ways to keep your data secure, but Secucenter offers you a more concentrated solution called SOC monitoring. Our SOC engineers will be proactive in monitoring your systems and endpoints for unusual activities and report in case it is detected. This has been beneficial for businesses, allowing them to clock out or take a break without worrying about exposing their confidential information.

Leave a Reply

Your email address will not be published. Required fields are marked *

The Author

Sreekanth

SOC Manager

Sreekanth is the SOC Manager at Secucenter with over 12 years of experience in cybersecurity and IT operations. His expertise includes infrastructure management, security implementation, security monitoring, threat detection, incident response, and SOC operations across on-premises, hybrid, and cloud environments. He focuses on building effective SOC processes and teams that combine people, processes, and technology to deliver reliable and customer-focused security operations.

FEATURED INSIGHTS

Security Intelligence
Hub

The True Cost of 24/7 In-House Cybersecurity Operations in 2026

Your business is surrounded by sharks waiting to take a bite of...

Read more ›

What the CDSL Malware Attack Teaches Organizations About VAPT?

Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...

Read more ›

The Human Firewall: What Kevin Mitnick Can Teach Us About Financial Fraud Today

The world's most famous hacker never needed to "hack" much Kevin Mitnick...

Read more ›

Stop guessing where you're exposed.
Talk to a senior analyst this week.

Get a Free Security Audit

Protect Your Business Today To Scale Tomorrow

Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.

Phone

+1 607 360 5504

Sales Office - United States

651, N Broad St, Middletown
Delaware-19709

Operations Center- India

Level 17, TransAsia Cyber Park
Kochi, Kerala-682030

Data privacy notice. All submissions are protected via TLS 1.3 encryption in transit and processed within our secure, air-gapped data environment. We never resell your data.