{"id":189,"date":"2020-09-12T04:09:40","date_gmt":"2020-09-12T04:09:40","guid":{"rendered":"https:\/\/www.gsecurelabs.com\/?p=189"},"modified":"2025-11-10T07:59:55","modified_gmt":"2025-11-10T07:59:55","slug":"citrix-data-breach-by-iridium-hackers-8-security-measures-to-prevent-it","status":"publish","type":"post","link":"https:\/\/www.gsecurelabs.com\/insights\/citrix-data-breach-by-iridium-hackers-8-security-measures-to-prevent-it\/","title":{"rendered":"Citrix Data Breach by Iridium Hackers: 8 Security Measures to Prevent IT"},"content":{"rendered":"<p>Citrix Systems, Inc. is an American multinational software company that provides server, application &amp; desktop virtualization, networking, software as a service (SaaS), and cloud computing technologies. Citrix solutions are claimed to be in use by over 400,000 clients worldwide, including 99% of the Fortune 100, and 98% of the Fortune 500.<\/p>\n<h4 class=\"title pt-4\">The Attack<\/h4>\n<p>In the month of March, FBI alerted Citrix that Iran base hackers going by the name of Iridium has attacked the company\u2019s internal network and stolen\/downloaded 6TB of highly sensitive data. They leveraged a combination of tools, techniques and procedures that allowed them to conduct network intrusion so that they could get the network\u2019s access.<\/p>\n<p>\u201cCitrix deeply regrets the impact this incident may have on affected customers. Citrix is committed to updating customers with more information as the investigation proceeds, and to continuing to work with the relevant law enforcement authorities,\u201d said Black, CSIO of Citrix.<\/p>\n<h4 class=\"title pt-4\">Hacker Tactics<\/h4>\n<p>As per FBI, the hacker used a tactic known as password spraying and credential stuffing. Password spraying is a technique used for a cyber attack against a weak password to compromise the first level of security and then move ahead to break the additional security layer. Credential stuffing involves stealing a password from data dumps and using them to access other services compromising the security and services. This way hackers managed to access and download the sensitive files.<\/p>\n<h4 class=\"title pt-4\">Post Investigation Report<\/h4>\n<p>Based on the investigation, Citrix confirmed that hackers had intermittent access to the company\u2019s network between 13-October-2018 to 08-March-2019 and they have removed files from the Citrix internal system. Stolen data contains current and former employees and information about the beneficiaries, social security number and financial information.<\/p>\n<h4 class=\"title pt-4\">Security Measures to Prevent Such Data Breach:<\/h4>\n<div class=\"blog-ui-style-custom-container pb-md-4 pb-32\">\n<ul class=\"blog-ui-style-custom\">\n<li><span class=\"gradiant-bg\">1<\/span>Enable multi-factor authentication (e.g. Google Keys)<\/li>\n<li><span class=\"gradiant-bg\">2<\/span>Enable captcha in some situations<\/li>\n<li><span class=\"gradiant-bg\">3<\/span>Blacklist the IP that originates from a few (or one) IP. Block addresses attempting to log into multiple accounts.<\/li>\n<li><span class=\"gradiant-bg\">4<\/span>Generate alerts for the account whose threshold limit is reached to maximum<\/li>\n<li><span class=\"gradiant-bg\">5<\/span>Notify users and concern teams about the unusual security events<\/li>\n<li><span class=\"gradiant-bg\">6<\/span>Adopt the policy of multi-step login process for (e.g. 2AF and Multi-factor Authentication)<\/li>\n<li><span class=\"gradiant-bg\">7<\/span>Limit the access outside the office<\/li>\n<li><span class=\"gradiant-bg\">8<\/span>Ban simple password and educate users to use a complex password with password managers<\/li>\n<\/ul>\n<\/div>\n<h4 class=\"title\">Citrix\u2019s Solution and Future Prevention<\/h4>\n<p>To find a solution to this data breach and future prevention Citrix partnered with leading cyber security firm to assist their internal team with its forensic investigation. They are also cooperating with the FBI in connection with their investigation of the cybercriminals.<\/p>\n<p class=\"fw-700 mb-0 pt-4\">Do you feel secure enough for your sensitive data?<\/p>\n<p>If no, hurry up and get <a class=\"yellow-text fw-700\" href=\"https:\/\/www.gsecurelabs.com\/insights\/security-assessment\/\">free security assessment<\/a> from us.<\/p>","protected":false},"excerpt":{"rendered":"<p>Citrix Systems, Inc. is an American multinational software company that provides server, application &amp; desktop virtualization, networking, software as a service (SaaS), and cloud computing technologies [&#8230;]<\/p>\n","protected":false},"author":1,"featured_media":190,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[14],"tags":[26,231,27,232,230,28,229],"class_list":["post-189","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-citrix-data-breach","tag-citrixs-solution","tag-data-breach","tag-future-prevention","tag-hacker-tactics","tag-network-security","tag-security-measures"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/posts\/189"}],"collection":[{"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/comments?post=189"}],"version-history":[{"count":0,"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/posts\/189\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/media\/190"}],"wp:attachment":[{"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/media?parent=189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/categories?post=189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsecurelabs.com\/insights\/wp-json\/wp\/v2\/tags?post=189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}