Cybernews reports that a threat actor claiming to have breached the enterprise intelligence software provider Infodesk has put up the compromised data for sale on a dark web forum.The sample provided by the attacker included five records from each of 18 companies and InfoDesk but claims to possess up to 1,000 records. The exposed employee information reportedly includes corporate email addresses and full names. The database contains employee records from organizations such as AARP, Kenvue, IMF, Kearney, Olympus, Abbott, Medtronic, Novonesis, Vertex, Sanofi, Bayer, GSK, Johnson & Johnson, Merck, Novo Nordisk, Moderna, Argenx, and UCB."The impact here is primarily about targeted phishing attacks. With a verified list of names and emails from a specific vendor like InfoDesk, an attacker can craft highly convincing messages to harvest credentials or deploy malware within these organizations," researchers noted. Other cyberattacks on third-party services include the the phishing incident involving Tata Consulting Services employees, which led to the breach of M&S network and the breach on the Crunchyroll streaming service caused by a compromise at Telus.
Data Security, Supply chain
Hacker alleges InfoDesk breach affecting pharma, financial firms

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



