US-based enterprise software firm JumpCloud announced it was the victim of a sophisticated cyber-attack carried out by a state-backed hacking group.
JumpCloud is a cloud-based directory service platform designed to manage user identities, devices, and applications in a seamless and secure manner. It allows IT administrators to centralize and simplify their identity and access management tasks across various systems and applications.
The company revealed it was hit by a nation-state cyberattack that targeted specific customers. In response to the attack, JumpCloud has invalidated all existing API keys to protect its customer’s operations.
The attack was discovered by the company on June 27, one week after the threat actors breached its network via a spear-phishing campaign.
The company initiated an investigation into the incident with the help of law enforcement and cybersecurity experts. The investigation confirmed that the attack was extremely targeted and aimed at specific customers.
JumpCloud is yet to provide any information on the number of customers impacted by the attack and they did not attribute the attack to a specific threat actor.
Founded in 2013, the JumpCloud directory-as-a-service platform provides single sign-on and multi-factor authentication services to over 180,000 organizations in more than 160 countries.














Comments