Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Ad Tech Company Optimizely Targeted in Cyberattack

The company says the attackers accessed internal business systems such as Zendesk and Salesforce.

Advertising firm cyberattack

Ad tech firm Optimizely has confirmed that threat actors accessed certain internal business systems through a sophisticated voice phishing (vishing) attack.

The incident, the company told SecurityWeek, was immediately contained, the affected systems were secured, and the unauthorized access was terminated.

“The threat actor gained access to Optimizely’s systems through a sophisticated voice-phishing attack, but was unable to escalate privileges, install software, or create any backdoors in the Optimizely environment,” the company said.

Optimizely says it has no evidence of any sensitive customer data or personal information being compromised in the attack, but has proactively notified its customers of the incident.

The company said the incident did not disrupt its operations and confirmed that the attackers were able to access business contact information.

“The incident was confined to certain internal business systems including Zendesk, records in our Salesforce CRM, and a limited set of internal documents used for back-office operations,” the company said.

Advertisement. Scroll to continue reading.

Optimizely has notified law enforcement of the attack and has engaged third-party cybersecurity experts and legal counsel to aid with the investigation.

“We are prioritizing transparency with our customers and partners; we have informed them of the incident and its scope and are continuing to provide updates and individual guidance to them directly,” the ad tech firm told SecurityWeek.

Optimizely did not name the threat actor behind the attack, but its description of the incident suggests that the infamous ShinyHunters extortion group might have been responsible for it.

Based in New York, Optimizely provides a digital experience platform enabling organizations to improve their websites and digital content.

It operates 21 offices worldwide, has nearly 1,500 employees, and provides services to more than 10,000 businesses, including H&M, PayPal, Toyota, Vodafone, and Zoom.

Related: US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

Related: PayPal Data Breach Led to Fraudulent Transactions

Related: Nearly 1 Million User Records Compromised in Figure Data Breach

Related: Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.