CISA is investigating a breach at business intelligence company Sisense; sources: the attackers copied several terabytes of customer data, including credentials
The reported theft of customer data and credentials makes this more than an internal Sisense event. Later coverage of attackers using compromised credentials to enter Cisco’s development environment illustrates why exposed access material can extend an intrusion beyond the initially breached company.
First-order effects
Sisense and its customers must assess which data and credentials were copied, rotate affected access material, and determine whether customer environments require containment.
CISA’s involvement brings federal incident-response scrutiny to the breach and increases pressure for a verified account of the exposure’s scope and access path.
Second-order effects
Customers that connected Sisense to cloud, analytics, or internal systems may need to review integrations and authentication logs, adding operational work beyond data-notification decisions.
The incident reinforces demand for controls around credential storage, repository access, and third-party access paths; CISA’s reported concern over credential exposure tied to public GitHub use highlights the same control boundary.
Third-order effects
If credential theft continues to be a common route from a vendor breach into customer systems, enterprise buyers will place more weight on vendors’ identity controls and incident-response transparency, not only their application features.
The pattern points toward ecosystem cyber defense: security accountability increasingly follows data and credentials across suppliers, contractors, and customers rather than stopping at the initially compromised company.
The trend: Vendor breaches are becoming ecosystem incidents as stolen credentials and connected customer data create routes into organizations beyond the original target.
New reporting from @briankrebs sheds some light on why CISA might have sounded the alarm so quickly on the Sisense hack. — “Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth of Sisense customer data, which apparently included mill…
The nature of sisense is they require access to their customers confidential data sources. They have direct access to JDBC connections, to SSH, and to SaaS platforms like Salesforce and many more. It also means they have tokens, credentials, certificates often upscoped. 1/2
Massive data breach at SiSense - a business intelligence platform. Actors allegedly compromised network, exfiltrated data and could potentially contain customer data. Highly recommend if using SiSense, to look at the following: * Change passwords of any SiSense accounts...
⚠️ We are collaborating with partners to respond to a recent compromise—discovered by independent security researchers—impacting Sisense. For more info, check out: https://cisa.gov/...
The data stolen from sisense contained all these tokens, credentials and access configurations. This is a worst case scenario for many sisense customers. These are often literally the keys to their kingdoms. Treat as an EXTREMELY serious event. 2/2
CISA is now recommending all Sisense customers revoke all credentials shared with Sisense, following an attacker abusing an AWS key Sisense had laying around in a Git repo. We (@trufflesec ) made https://howtorotate.com/ a while ago to make revocation as painless as we can. [imag…
Sisense has released specific instructions to its customers. On the one hand it's easy to be mad at this situation, the plaintext storage of credentials and the insecure storage of data at rest. On the other had I want to give them props for reaching this point in under 24... [im…
Once the dust settles on the sisense breach, can we all sit down and have a serious conversation about access and score? Not having a traditional perimeter doesn't mean throwing your doors open and allowing uncontrolled access into critical systems.
If you are, or ever were a sisense customer, Treat this extremely seriously. Members of the cyber community and agencies all over the world have worked this over the last few days. Do not underestimate the risk. Expire any exposed credentials. Check all exposed infrastructure.
STRONG RECOMMENDATION - If you are a CISO and you have a 3rd party (Automation, AI, Analytics) that uses Sisense or you SUSPECT uses Sisense INSIST on an impact statement NOW. I can 100% guarantee there are a lot of you with impact. Your data was accessed by a threat actor.
Sisense is one of those tools you connect to a lot of other sensitive things. So things their customers need to go kill, rotate, check logs on: Salesforce, BigQuery, Snowflake, and even ssh keys?! [video]