/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

CISA is investigating a breach at business intelligence company Sisense; sources: the attackers copied several terabytes of customer data, including credentials

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said today it is investigating a breach at business intelligence …

Krebs on Security Brian Krebs

Context & Ripple Effects

CISA’s investigation puts Sisense in a wider operational-security arc: the agency had already taken two of its own systems offline after detecting Ivanti exploitation, underscoring that incident response can require service disruption as well as remediation.

The reported theft of customer data and credentials makes this more than an internal Sisense event. Later coverage of attackers using compromised credentials to enter Cisco’s development environment illustrates why exposed access material can extend an intrusion beyond the initially breached company.

First-order effects

  • Sisense and its customers must assess which data and credentials were copied, rotate affected access material, and determine whether customer environments require containment.
  • CISA’s involvement brings federal incident-response scrutiny to the breach and increases pressure for a verified account of the exposure’s scope and access path.

Second-order effects

  • Customers that connected Sisense to cloud, analytics, or internal systems may need to review integrations and authentication logs, adding operational work beyond data-notification decisions.
  • The incident reinforces demand for controls around credential storage, repository access, and third-party access paths; CISA’s reported concern over credential exposure tied to public GitHub use highlights the same control boundary.

Third-order effects

  • If credential theft continues to be a common route from a vendor breach into customer systems, enterprise buyers will place more weight on vendors’ identity controls and incident-response transparency, not only their application features.
  • The pattern points toward ecosystem cyber defense: security accountability increasingly follows data and credentials across suppliers, contractors, and customers rather than stopping at the initially compromised company.

The trend: Vendor breaches are becoming ecosystem incidents as stolen credentials and connected customer data create routes into organizations beyond the original target.

Discussion

  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    New reporting from @briankrebs sheds some light on why CISA might have sounded the alarm so quickly on the Sisense hack.  —  “Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth of Sisense customer data, which apparently included mill…
  • @marcwrogers Marc Rogers on x
    The nature of sisense is they require access to their customers confidential data sources. They have direct access to JDBC connections, to SSH, and to SaaS platforms like Salesforce and many more. It also means they have tokens, credentials, certificates often upscoped. 1/2
  • @hackingdave Dave Kennedy on x
    Massive data breach at SiSense - a business intelligence platform. Actors allegedly compromised network, exfiltrated data and could potentially contain customer data. Highly recommend if using SiSense, to look at the following: * Change passwords of any SiSense accounts...
  • @cisacyber @cisacyber on x
    ⚠️ We are collaborating with partners to respond to a recent compromise—discovered by independent security researchers—impacting Sisense. For more info, check out: https://cisa.gov/...
  • @marcwrogers Marc Rogers on x
    The data stolen from sisense contained all these tokens, credentials and access configurations. This is a worst case scenario for many sisense customers. These are often literally the keys to their kingdoms. Treat as an EXTREMELY serious event. 2/2
  • @insecurenature Dylan on x
    CISA is now recommending all Sisense customers revoke all credentials shared with Sisense, following an attacker abusing an AWS key Sisense had laying around in a Git repo. We (@trufflesec ) made https://howtorotate.com/ a while ago to make revocation as painless as we can. [imag…
  • @marcwrogers Marc Rogers on x
    Sisense has released specific instructions to its customers. On the one hand it's easy to be mad at this situation, the plaintext storage of credentials and the insecure storage of data at rest. On the other had I want to give them props for reaching this point in under 24... [im…
  • @marcwrogers Marc Rogers on x
    Once the dust settles on the sisense breach, can we all sit down and have a serious conversation about access and score? Not having a traditional perimeter doesn't mean throwing your doors open and allowing uncontrolled access into critical systems.
  • @cheddarb0b42 @cheddarb0b42 on x
    “which apparently included millions of access tokens, email account passwords, and even SSL certificates” 💀🪦 Krebs: https://krebsonsecurity.com/ ...
  • @marcwrogers Marc Rogers on x
    If you are, or ever were a sisense customer, Treat this extremely seriously. Members of the cyber community and agencies all over the world have worked this over the last few days. Do not underestimate the risk. Expire any exposed credentials. Check all exposed infrastructure.
  • @marcwrogers Marc Rogers on x
    STRONG RECOMMENDATION - If you are a CISO and you have a 3rd party (Automation, AI, Analytics) that uses Sisense or you SUSPECT uses Sisense INSIST on an impact statement NOW. I can 100% guarantee there are a lot of you with impact. Your data was accessed by a threat actor.
  • @mattjay Matt Johansen on x
    Sisense is one of those tools you connect to a lot of other sensitive things. So things their customers need to go kill, rotate, check logs on: Salesforce, BigQuery, Snowflake, and even ssh keys?! [video]