{
  "type": "bundle",
  "id": "bundle--360c24fc-1f3d-5ca1-8e70-fa20ba127286",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--ccea5c25-f57c-56f6-8121-8fe98925a776",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:ae47e539-5814-5894-8de1-63b5b9c2248f",
      "name": "Cisco",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--b1f1ee73-d776-5f95-8e46-946744d3f29f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:dfec8553-3e5e-5ac0-87d4-229d1eeda92e",
      "name": "Cisco security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--c8f9112e-f64c-58cb-863d-1efccc0b3c0f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:5c474365-9d66-5ac6-a4dc-c00e8e84e084",
      "name": "Cisco security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9e3854af-0aaa-52b5-8929-8aa337079ca9",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:450310e2-d7a6-5abc-a5b4-178027530297",
      "relationship_type": "affected-organization",
      "source_ref": "incident--b1f1ee73-d776-5f95-8e46-946744d3f29f",
      "target_ref": "identity--ccea5c25-f57c-56f6-8121-8fe98925a776",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Cisco Talos",
          "url": "https://blog.talosintelligence.com/recent-cyber-attack/",
          "external_id": "cit:494e5a6a-2a08-5a87-91df-8e968883cced",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a254d1d36072fd0cf9b8ce3a47ba468931589c169fe455839fc1f869d3b7bd5a"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--25910784-bde5-5731-85a6-8047f09ae368",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:a4c74037-e9f0-5ffb-be71-46da2403c60a",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Cisco Talos",
          "url": "https://blog.talosintelligence.com/recent-cyber-attack/",
          "external_id": "cit:7313a671-f555-555b-a235-07ac9e353bfd",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a0292e933406db2fcfd63f8761bb9bef149226e00638b846e5c249ded5189dc2"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "date",
        "value": "2022-08-10"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--30e20fdb-efb2-5bbb-8f5f-951f9e696944",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:ffde61b0-b3d2-58dc-97d6-959e0711ce54",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "Cisco Talos",
          "url": "https://blog.talosintelligence.com/recent-cyber-attack/",
          "external_id": "cit:48361bbb-897d-55a4-a69f-a5150d14ec50",
          "description": "Since that point, Cisco Security Incident Response (CSIRT) and Cisco Talos have been working to remediate. - During the investigation, it was determined that a Cisco employee’s credentials were compromised after an attacker gained control of a personal Google account where credentials saved in the victim’s browser were being synchronized. - The attacker conducted a series of sophisticated voice phishing attacks under the guise of various trusted organizations attempting to convince the victim to accept multi-factor authentication (MFA) push notifications initiated by the attacker.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a0292e933406db2fcfd63f8761bb9bef149226e00638b846e5c249ded5189dc2"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Yanluowang group; employee's personal Google account synced corporate credentials, plus voice phishing and MFA fatigue."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--53df9dd3-ffbb-595c-8048-35210b35d490",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:2fc584fd-7d97-54ff-8fb0-c7804f697d72",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1621/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--57718c57-c4ad-5d08-8f17-aab9b60cdd39",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:a0ce849d-1c62-53a0-9587-189f534db8ef",
      "confidence": 85,
      "external_references": [
        {
          "source_name": "Cisco Talos",
          "url": "https://blog.talosintelligence.com/recent-cyber-attack/",
          "external_id": "cit:4e4e71bc-9f14-5a22-80e4-fa2515a0d5b8",
          "description": "UNC2447 is a financially-motivated threat actor with a nexus to Russia that has been previously observed conducting ransomware attacks and leveraging a technique known as “double extortion,” in which data is exfiltrated prior to ransomware deployment in an attempt to coerce victims into paying ransom demands.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a0292e933406db2fcfd63f8761bb9bef149226e00638b846e5c249ded5189dc2"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "No ransomware deployed; some non-sensitive files exfiltrated."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--73e2e7a5-7022-5bc0-81c8-9b6a85f27b52",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:db2e4118-717c-5ec3-be12-4b819ed9047e",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Cisco Talos",
          "url": "https://blog.talosintelligence.com/recent-cyber-attack/",
          "external_id": "cit:c481fdd7-5d1f-5a55-95bd-22c2099dac3b",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:a254d1d36072fd0cf9b8ce3a47ba468931589c169fe455839fc1f869d3b7bd5a"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the cisco security incident involving Cisco."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--84f250ac-cb1c-5627-8000-6b0d109b66ff",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:a34f9b1c-0b50-5f51-b04f-5fc93eb47957",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1566/"
      }
    },
    {
      "type": "x-ally-event",
      "spec_version": "2.1",
      "id": "x-ally-event--e7197a41-979b-506b-821d-ef9afc28d413",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "evt:d82c40e8-832e-55a5-b7f6-c8eb7874c76d",
      "name": "Documented public update"
    }
  ]
}
