In February 2025, the Kraken ransomware group posted a list of Cisco Windows Active Directory credentials on its new leak site: usernames, domain identifiers and NTLM password hashes, reportedly including privileged administrator accounts, service and machine accounts and the domain's krbtgt account, which signs Kerberos tickets. The post suggested Cisco was still trying to remove the group from its network. Cisco denied a new breach. "The incident referenced in the reports occurred back in May 2022, and we fully addressed it at that time," a spokesperson said. "Based on our investigation there was no impact to our customers." SecurityWeek noted that Kraken appears to be a rebrand of the HelloKitty ransomware group, linked to the actors behind the 2022 Cisco intrusion, which explains why it held the data.
Key takeaways
- Kraken published Cisco Active Directory usernames, identifiers and NTLM hashes, reportedly including admin, service and machine accounts and krbtgt.
- Cisco says the data comes from its May 2022 incident, which it fully addressed, and that customers were not affected.
- Kraken appears to be a rebranding of HelloKitty, whose associates were linked to the 2022 attack, and may have republished old data to promote the new name, SecurityWeek reported.
- The group's suggestion of an ongoing intrusion is a claim that Cisco denies.
- The identity lesson: once directory hashes are stolen, every account in them, including service accounts and krbtgt, must be rotated, or old data stays dangerous for years.
At a glance
| Organisation | Cisco Systems |
|---|---|
| When | Data originally stolen in May 2022; republished by Kraken in February 2025 |
| Attacker | The Kraken ransomware group, which appears to be a rebrand of HelloKitty; the 2022 attack was attributed to an initial access broker linked to UNC2447, Lapsus$ and Yanluowang |
| Entry point | The 2022 intrusion began with a compromised employee's personal Google account and vishing to bypass MFA; no new entry point is known |
| Identities abused | Active Directory account hashes, reportedly including privileged administrator, service and machine accounts and the krbtgt account |
| Impact | Old credential data republished; Cisco says the incident was fully addressed in 2022 with no customer impact; a new intrusion is claimed but denied |
| Category | NHI. Incident class: claimed breach (republished 2022 directory credentials; new intrusion claim denied) |
What happened
Over the weekend of 8 and 9 February 2025, SecurityWeek reported, a list of credentials apparently taken from Cisco's systems appeared on a new leak site run by the Kraken ransomware group. According to Cyber Press reporting cited by teiss and ITPro, the data included usernames, domains, relative identifiers and NTLM password hashes for privileged administrator accounts, standard users, service and machine accounts, and the domain's Kerberos ticket-granting account. ITPro reported that the post threatened future attacks and suggested Cisco had been trying, unsuccessfully, to remove the group from its network.
Cisco's response was that this was old data. "Cisco is aware of certain reports regarding a security incident. The incident referenced in the reports occurred back in May 2022, and we fully addressed it at that time. Based on our investigation there was no impact to our customers." In 2022, attackers had taken over an employee's personal Google account that stored company credentials, used vishing to get past MFA and reached the VPN. Cisco attributed that attack to an initial access broker linked to UNC2447, Lapsus$ and the Yanluowang ransomware operation, and the stolen files were leaked in September 2022.
SecurityWeek noted that "Kraken appears to be a rebranding of the HelloKitty ransomware group, as referenced on the leak site, which explains why they have the Cisco data in possession," and that the group was "likely looking to draw attention to the new brand by resurfacing older hacks." Our page on the 2022 Cisco breach covers the original intrusion.
Timeline
| Date | Event |
|---|---|
| May 2022 | Cisco's network is breached; Cisco later says it fully addressed the incident. |
| August 2022 | Cisco publishes details of the 2022 attack. |
| September 2022 | Files stolen in the 2022 attack are leaked. |
| February 2025 | Kraken publishes Cisco Active Directory credentials on its leak site. |
| 12 February 2025 | Cisco says the data relates to the May 2022 incident, as reported by SecurityWeek and teiss. |
How it happened: the identity attack path
- 2022 initial access. Attackers used an employee's compromised personal Google account and vishing to reach Cisco's VPN.
- Credential dumping. During that intrusion, directory credentials and hashes were collected; teiss notes analysts suspect tools such as Mimikatz.
- Data retained. The group, later rebranded as Kraken, kept the stolen data.
- Republication. In February 2025 the hashes were posted again, with claims of continued access.
- Vendor response. Cisco says the incident was addressed in 2022 and customers were not affected.
Impact
- Confirmed by Cisco: the data comes from the May 2022 incident; no customer impact.
- Claimed, denied: an ongoing intrusion into Cisco's network.
- Potential: if any listed account had not been rotated since 2022, its hash could still be used for pass-the-hash or, for krbtgt, ticket forgery.
What this means for NHI governance
A directory dump includes more than people. Service accounts, machine accounts and krbtgt are non-human identities, and they are often the ones never rotated because changing them risks breaking applications or requires careful, repeated resets. That is why an old dump can stay dangerous: human passwords get changed through normal churn, but a service account password or the krbtgt secret may be the same years later.
After any directory compromise, the recovery plan must cover every non-human account in the dump, including a double krbtgt reset, and should move service accounts to managed identities with automatic rotation. See our Active Directory and Entra ID Hardening Guide and Service Account Security Guide.
Recommendations
- Rotate every account in a stolen directory dump. Include service accounts, machine accounts and privileged admins. See the Leaked Credential Response Playbook.
- Reset krbtgt twice after a domain compromise. This invalidates tickets forged with the old secret. See the Active Directory and Entra ID Hardening Guide.
- Use managed service accounts. Group managed service accounts rotate passwords automatically. See the Service Account Security Guide.
- Monitor for pass-the-hash and forged tickets. Detection helps if an old credential is reused. See the ITDR Guide.
- Treat republished data as a prompt to verify. Check that every exposed credential was actually rotated, even if the incident is years old.
Frequently asked questions
Was Cisco breached again in 2025?
Cisco says no. The Active Directory credentials Kraken published come from the May 2022 incident, which Cisco says it fully addressed with no customer impact. Kraken's suggestion of an ongoing intrusion is unconfirmed.
What did the Kraken leak contain?
Usernames, domain identifiers and NTLM password hashes from Cisco's Windows Active Directory, reportedly including privileged administrator, service and machine accounts and the krbtgt account.
Why does old leaked credential data still matter?
Accounts that were never rotated, especially service accounts and krbtgt, remain usable with old hashes. Every account in a dump must be rotated to make it harmless.
Related NHI Mgmt Group resources
Cisco Breach 2022 · Cisco DevHub Breach 2024 · Active Directory and Entra ID Hardening Guide · Service Account Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Directory recovery plans often forget the non-human accounts. We help teams find service and machine accounts, rotate them safely and move to managed identities. See our NHI and AI agent security training.
References
- SecurityWeek: Cisco Says Ransomware Group's Leak Related to Old Hack (12 February 2025)
- teiss: Cisco refutes Kraken ransomware group's data breach claims (12 February 2025)
- ITPro: Cisco dispels Kraken data breach claims, insists stolen data came from old attack (February 2025)