Australian software giant Atlassian and workplace management startup Envoy came into conflict on Thursday over a data breach that exposed the data of thousands of Atlassian employees.
As Cyberscoop first reported, a hacking group known as SiegedSec leaked data on Telegram this week that it claimed to have stolen from Atlassian. This data includes the names, emails, departments, and phone numbers of approximately 13,200 Atlassian employees, as well as floor plans for Atlassian offices in San Francisco and Sydney, Australia.
“SiegedSec is here to announce that it has hacked software company Atlassian,” SiegedSec said in a Telegram message seen by TechCrunch. “This company worth $44 billion has been hijacked by hairy hackers uwu.” SiegedSec made headlines last year and beyond leaked 8 gigabytes of data from the Kentucky and Arkansas governments. Following the Supreme Court’s decision to overturn Roe v. Wade, we are protesting state government efforts to enact an abortion ban.
Atlassian was quick to point responsibility for the breach at Envoy, which the Sydney-based company uses to organize its office space. “On February 15, 2023, I learned that her Envoy data, a third-party app that Atlassian uses to coordinate resources within the office, was compromised and made public,” she said. Atlassian spokeswoman Megan Sutton said in a statement shared on her TechCrunch. “Atlassian’s product and customer data is not accessible through her Envoy app, so there is no risk.”
However, Envoy quickly rejected Atlassian’s claims. Envoy spokesperson April Marks told TechCrunch that the company “is not aware of any compromises to our systems,” and initial investigations revealed that “hackers accessed valid credentials of Atlassian employees. and then pivoted to access the Atlassian payroll and office floor,” he added. A plan held within the Envoy app. Envoy declined to provide evidence for its claims or to answer specific questions.
Shortly after the startup’s denial, Atlassian changed its stance to work more closely with Envoy. Atlassian’s Sutton told TechCrunch that the company’s internal investigation revealed that the attacker had indeed compromised his Atlassian data from his Envoy app.
“The hacking group therefore had access to data viewed through employee accounts, including public office floor plans and public Envoy profiles of other Atlassian employees and contractors,” Sutton said. added Mr. “The compromised employee’s account was immediately disabled, eliminating further threats to Atlassian’s Envoy data. Atlassian’s product and customer data is not accessible via his Envoy app, which puts it at risk.” You will not be exposed.”
Envoy apparently wasn’t responsible for Atlassian’s data breach, but the workplace management startup Envoy, which has many high-profile customers such as Hulu, Pinterest, Slack, and Stripe, is no stranger to security incidents. In 2019, security researchers at IBM discovered two flaws in Envoy’s visitor management system that could expose her to customer data.