Reports indicate that Cisco experienced an alleged partial data breach stemming from a supply chain compromise of the Trivy security scanner. The cybercriminal group ShinyHunters claimed responsibility on March 31, 2026, with an extortion deadline set for April 3, 2026. Credentials were reportedly stolen around March 1, 2026, which provided initial access.
ShinyHunters claims over 3 million Salesforce records containing personally identifiable information (PII) were compromised. Additionally, over 300 GitHub repositories, including AI project source code, AWS keys, EC2, S3 bucket access, hardcoded credentials, and API tokens, are also alleged to have been exposed. Cisco has not yet released an official statement addressing the ShinyHunters' claims.
Details surrounding the full extent of the alleged breach and confirmation from Cisco are still emerging. Official statements and verified information regarding affected individuals or specific states are not yet publicly available.