Hackers steal data from Citrix


San Francisco, Mar 11 (IANS): Iran-based hackers have stolen terabytes of data from desktop virtualisation leader Citrix, with the company admitting that the cyber criminals may have accessed and downloaded business documents.

"The specific documents that may have been accessed, however, are currently unknown. At this time, there is no indication that the security of any Citrix product or service was compromised," Citrix Chief Information Security Officer Stan Black said in a blog post.

According to a report in The Registrar on Sunday, the Federal Bureau of Investigation (FBI) last week warned Citrix about the data hack.

According to cyber security firm Resecurity, at least six terabytes of sensitive internal files were stolen by the Iranian-backed IRIDIUM hacker gang.

The researchers said they had alerted Citrix as early as December 28 last year about the ongoing attack.

"Citrix has taken action to contain the incident. We commenced a forensic investigation; engaged a leading cyber security firm to assist; took actions to secure our internal network; and continue to cooperate with the FBI," Black wrote.

The hackers probably used a tactic known as "password spraying", which exploits weak passwords. Once they gain a foothold with limited access, they worked to circumvent additional layers of security.

"Citrix deeply regrets the impact this incident may have on affected customers," he said.

  

Top Stories


Leave a Comment

Title: Hackers steal data from Citrix



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.