Security News > 2023 > July > JumpCloud breach traced back to North Korean state hackers
US-based enterprise software company JumpCloud was breached by North Korean Lazarus Group hackers, according to security researchers at SentinelOne and CrowdStrike.
In a report published on Thursday, SentinelOne Senior Threat Researcher Tom Hegel linked the North Korean threat group to the JumpCloud hack based on multiple indicators of compromise shared by the company in a recent incident report.
"Reviewing the newly released indicators of compromise, we associate the cluster of threat activity to a North Korean state sponsored APT," said Hegel.
Cybersecurity firm CrowdStrike also formally tagged Labyrinth Chollima as the particular North Korean hacking squad behind the breach based on evidence found while investigating the attack in collaboration with JumpCloud.
As of now, JumpCloud has not disclosed the number of customers impacted by the attack and has not attributed the APT group behind the breach to a specific state.
JumpCloud discloses breach by state-backed APT hacking group.
News URL
Related news
- Fortinet confirms data breach after hacker claims to steal 440GB of files (source)
- North Korean Hackers Target Cryptocurrency Users on LinkedIn with RustDoor Malware (source)
- Temu denies breach after hacker claims theft of 87 million data records (source)
- North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware (source)
- Hackers Exploit Default Credentials in FOUNDATION Software to Breach Construction Firms (source)
- Dell investigates data breach claims after hacker leaks employee info (source)
- North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks (source)
- USDoD hacker behind National Public Data breach arrested in Brazil (source)
- North Korean govt hackers linked to Play ransomware attack (source)
- North Korean hackers pave the way for Play ransomware (source)