A notorious hacker, known as IntelBroker, has leaked 2.9GB of data allegedly stolen from Cisco’s DevHub environment. This partial leak, disclosed on December 16, 2024, is part of a broader breach estimated to involve up to 4.5TB of sensitive data.
The incident has raised significant concerns about the cybersecurity practices of one of the world’s leading IT and networking companies.
Details of the Breach
The breach reportedly originated from Cisco’s public-facing DevHub portal, which IntelBroker claims was left exposed due to inadequate security measures. Collaborators identified as “@zjj” and “@EnergyWeaponUser” exploited an exposed API token to access sensitive resources.
The compromised data, amounting to 2.9GB in this leak, allegedly includes:
- Source code from GitHub, GitLab, and SonarQube projects.
- Hardcoded credentials, API tokens, and certificates.
- Confidential documents, including Jira tickets and Docker builds.
- Cloud storage data from AWS and Azure buckets.
- Encryption keys, SSL certificates, and files related to Cisco’s premium software products.
IntelBroker’s leaked files pertain to several critical Cisco technologies, including Cisco IOS XE & XR, Cisco ISE, Cisco Umbrella, Cisco Webex.
IntelBroker alleges the breach extends to data linked with major corporations such as Verizon, AT&T, Microsoft, Bank of America, Barclays, Vodafone, and Chevron. Compromised information reportedly includes production source codes and Secure Remote Connections (SRCs), potentially exposing these organizations to significant security risks.
IntelBroker initially announced the breach in October 2024 via BreachForums, a dark web platform. The recent leak serves to validate the hacker’s claims and attract potential buyers for the remaining dataset.
Cisco has acknowledged the incident and attributes the breach to a misconfigured DevHub environment designed for developers to access resources like software code and APIs. Public access to DevHub has since been disabled as the company continues its investigation.
Cisco stated that No sensitive PII or financial data has been identified in the exposed files and that the Law enforcement and cybersecurity experts have been engaged to assess the situation.
Despite assurances that its core systems remain intact, the exposure of source codes, credentials, and encryption keys raises concerns about potential downstream risks to customers and partners.
Cybersecurity experts warn that this breach highlights the persistent vulnerabilities of publicly accessible developer environments. Robust access controls, continuous monitoring, and proactive security measures are critical to mitigating such risks.
The incident underscores the urgent need for companies to fortify their defenses against evolving cyber threats.















Comments