How the Yanluowang Ransomware Group Hacked Cisco in 2022

In late May 2022, Cisco confirmed that attackers breached its corporate network and stole approximately 2.8GB of files, including NDAs, engineering drawings and data dumps. The Yanluowang ransomware group claimed responsibility and published a directory listing on their dark web leak site after Cisco refused to pay. What made this breach unusual was not the volume of data stolen but the method: attackers bypassed multi-factor authentication through a combination of credential theft, voice phishing and relentless push-notification spam. No ransomware was deployed, yet the incident revealed how initial access brokers operate before handing off victims to encryption crews.
What Happened in the Cisco Ransomware Attack
Cisco publicly disclosed the breach in August 2022, weeks after the initial intrusion in late May. The Yanluowang ransomware group gained access by compromising a single employee's personal Google account, which contained credentials synced from their web browser. Once the attackers harvested those credentials, they launched a campaign of voice phishing calls impersonating trusted support organizations while simultaneously flooding the employee with multi-factor authentication push requests.
This tactic, known as MFA fatigue, relies on overwhelming the target with notifications until they accept one just to stop the interruptions. The employee eventually approved a request, granting the attackers VPN access under the employee's identity. From that foothold, the group moved laterally to Citrix servers and eventually compromised domain controllers, gaining administrative privileges across the network.
Cisco detected the intrusion and removed the attackers, but the group made repeated attempts to regain access over the following weeks. All re-entry attempts failed. The attackers then published a directory listing of stolen files on their dark web leak site, claiming to hold 2.75GB of data across roughly 3,100 files. Cisco confirmed that only non-sensitive data from a Box folder linked to the compromised account was exfiltrated, with no impact to customer data, intellectual property or supply chain operations.
How the Yanluowang Ransomware Group Operates
The Yanluowang ransomware group emerged in the threat landscape as part of a broader ecosystem where initial access brokers sell network footholds to ransomware operators. Security researchers at the time assessed with moderate to high confidence that the actors behind the Cisco breach had ties to UNC2447, a cybercrime gang, and the Lapsus$ threat actor group, both known for aggressive social engineering and data extortion.
Unlike traditional ransomware attacks that encrypt files and demand payment for decryption keys, the Cisco data breach 2022 involved no ransomware deployment. Instead, the attackers focused on reconnaissance, privilege escalation and data theft. They used enumeration tools including ntdsutil, adfind and secretsdump to map the network and extract credentials. They also installed backdoor malware to maintain persistence and attempted to deploy a Windows privilege escalation exploit targeting CVE-2022-24521, a vulnerability in the Common Log File System Driver that had been patched by Microsoft in April 2022. Cisco confirmed the exploit attempts were unsuccessful.
The group's business model centers on extortion: steal sensitive data, threaten to publish it on a dark web leak site, and demand payment to keep it private. When Cisco refused, Yanluowang published the file directory as proof and leverage. This approach mirrors the double-extortion tactic popularized by other ransomware groups, but without the encryption step.
The Technical Details of the Breach
After gaining VPN access, the attackers moved quickly to establish control. They pivoted from the initial compromised account to Citrix servers, which provided access to virtualized desktops and applications used across the organization. From there, they targeted domain controllers, the servers that manage authentication and permissions for Windows networks. Gaining domain admin rights meant the attackers could create accounts, access any system and move freely without triggering many security alerts.
Cisco Talos, the company's threat intelligence division, documented the attacker's use of living-off-the-land techniques: leveraging legitimate administrative tools already present in the environment rather than introducing obvious malware. The enumeration tools they deployed are standard in penetration testing and red-team exercises, which made detection harder. The backdoor malware they installed allowed remote command execution, giving them a way to return even if primary access was cut off.
To help defenders identify similar intrusions, Cisco released ClamAV signatures for the backdoor and the privilege escalation exploit. The exploit binary, later identified on VirusTotal, targeted a vulnerability reported to Microsoft by the NSA and CrowdStrike. The fact that the exploit had been patched two months before the attack underscores a common reality: patch deployment lags behind disclosure, and attackers know it. Organizations that delay updates create windows of opportunity measured in weeks or months.

Why MFA Fatigue and Voice Phishing Work
Multi-factor authentication is designed to block attackers who steal passwords, but it assumes users will reject illegitimate authentication requests. MFA fatigue exploits the gap between security design and human behavior. When someone receives dozens of push notifications in rapid succession, the instinct to make them stop can override caution. The attackers in the Cisco breach combined this with voice phishing, calling the employee and impersonating IT support to create a sense of urgency and legitimacy.
This social engineering layer is what separates sophisticated threat actors from script kiddies. The attackers researched their target, identified the employee's role and access level, and crafted a scenario that felt plausible. The employee's personal Google account became the weak link because it stored work credentials synced from a browser, a common practice that blurs the line between personal and corporate security.
Organizations can mitigate MFA fatigue by switching from push-based authentication to number-matching prompts, where the user must enter a code displayed on the login screen. Even better, hardware security keys that use FIDO2 protocols eliminate phishing entirely because the cryptographic challenge cannot be proxied to an attacker. Cisco's own response included implementing additional safeguards, though the company did not specify which controls were added. The lesson is that MFA is not a single solution but a spectrum, and the weakest implementations offer only marginal protection against determined attackers.
What Cisco and the Security Community Learned
Cisco's public disclosure and the detailed technical writeup from Cisco Talos provided the security community with indicators of compromise, attack patterns and defensive recommendations. According to public incident reports from enterprise security vendors, this level of transparency helps other organizations tune their detection systems and update their threat models. The company's decision to share forensic details, including the tools and exploits used, reflects a broader shift toward collaborative defense in an environment where attackers share techniques freely on dark web forums.
Law enforcement agencies, including the FBI and CISA, have issued advisories on initial access brokers and the ransomware supply chain, noting that many breaches follow a similar pattern: credential theft, social engineering to bypass MFA, lateral movement using legitimate tools, and data exfiltration before any encryption occurs. Court records from ransomware prosecutions show that initial access is often sold on underground markets for thousands of dollars, with the buyer deciding whether to deploy ransomware, sell the data or both.
The Tor Project documentation on onion services explains that dark web leak sites, like the one Yanluowang used to publish the Cisco file listing, are hosted as hidden services to obscure the operators' location and identity. These sites serve as both extortion platforms and advertising: they demonstrate the group's capabilities to potential victims and buyers. For ordinary users and companies, the key insight is that breaches often begin with the simplest vector, a reused password or a moment of inattention, and escalate through automation and persistence. The technical sophistication comes after the initial foothold, not before.
The Broader Context of Ransomware and Data Extortion
The Cisco data breach 2022 sits within a larger trend where ransomware groups and their affiliates have shifted from pure encryption to data theft and extortion. This model reduces the technical burden of deploying ransomware while maintaining leverage over victims. Even if backups are intact and systems can be restored quickly, the threat of publishing proprietary data, customer records or internal communications can be enough to force payment.
Yanluowang also claimed to have breached Walmart around the same time, though Walmart denied finding any evidence of a ransomware attack. This pattern of claims and counterclaims is common in the extortion ecosystem. Threat actors sometimes exaggerate their access or recycle old data to inflate their reputation, while companies may downplay breaches to limit reputational damage. Independent verification is difficult because neither party has an incentive to share complete information.
For readers concerned about their own exposure, the practical takeaway is that credential hygiene and authentication strength matter more than perimeter defenses. Attackers do not need to find a zero-day vulnerability if they can trick an employee into approving an MFA request or reuse a password scraped from a personal account. The dark web marketplaces and forums where stolen credentials are sold operate openly, with listings for corporate VPN access, email accounts and cloud storage. The supply chain of cybercrime is professionalized, and the Cisco breach illustrates how quickly a single compromised account can escalate into a full network intrusion.
What You Can Do to Avoid Similar Breaches
The Cisco ransomware attack demonstrates that even well-resourced organizations with mature security programs can be breached through social engineering and credential theft. The first step for any individual or organization is to separate personal and work credentials completely. Do not sync work passwords to personal browsers or cloud accounts. Use a dedicated password manager with a strong master password and enable the most resistant form of MFA available, preferably hardware keys.
If your organization uses push-based MFA, advocate for number-matching or FIDO2 tokens. Train employees to recognize voice phishing and to verify any unexpected authentication requests through a separate communication channel, not the one the caller provides. Document a clear process for reporting suspicious activity without fear of blame, because early detection often depends on users admitting they made a mistake.
Monitor for signs of credential exposure by checking services that aggregate breach data, though be cautious about submitting work email addresses to third-party sites. Review access logs regularly and set up alerts for unusual login locations or times. The attackers in the Cisco breach persisted for weeks after the initial detection, probing for ways back in. Defense is not a one-time action but a continuous process of monitoring, updating and questioning assumptions. If you manage a network, the technical details Cisco published are worth studying not as a checklist but as a case study in how attackers think and move once inside.
Frequently asked questions
What is the Yanluowang ransomware group?
The Yanluowang ransomware group is a cybercrime operation linked to initial access brokers and other threat actors including UNC2447 and Lapsus$. They specialize in network intrusions, data theft and extortion, sometimes deploying ransomware but often relying solely on the threat of publishing stolen files on dark web leak sites. The group gained attention for breaching Cisco in 2022 using social engineering and MFA fatigue tactics.
How did attackers bypass Cisco's multi-factor authentication?
The attackers used a combination of credential theft and MFA fatigue. They first compromised an employee's personal Google account, which contained work credentials synced from a browser. Then they flooded the employee with multi-factor authentication push notifications while conducting voice phishing calls that impersonated IT support. Eventually, the employee approved one of the requests to stop the interruptions, granting the attackers VPN access.
Was ransomware deployed in the Cisco data breach 2022?
No, Cisco found no evidence that ransomware was deployed on its systems. The attackers focused on reconnaissance, privilege escalation and data exfiltration instead. Cisco Talos described the activity as pre-ransomware behavior, the kind of preparation that typically precedes encryption. The Yanluowang group used the stolen data for extortion, threatening to publish it on their dark web leak site when Cisco refused to pay.
What data did the Yanluowang group steal from Cisco?
The attackers claimed to have stolen approximately 2.75GB of data, consisting of around 3,100 files. Cisco confirmed that the stolen data came from a Box folder linked to the compromised employee's account and included non-disclosure agreements, data dumps and engineering drawings. The company stated that no sensitive customer data, employee information, intellectual property or supply chain data was affected.
How can I protect my organization from MFA fatigue attacks?
Switch from push-based MFA to number-matching prompts, where users must enter a code displayed on the login screen, or adopt hardware security keys that use FIDO2 protocols. Train employees to reject unexpected authentication requests and verify any suspicious activity through a separate communication channel. Implement rate limiting on MFA requests and monitor for patterns of repeated failed attempts. Separate personal and work credentials completely, and avoid syncing work passwords to personal browsers or cloud accounts.