Skip to main content
Cybersecurity News Kinetic Potential

Ad Tech Company Optimizely Targeted in Cyberattack

Ad tech firm Optimizely has confirmed that threat actors accessed certain internal business systems through a sophisticated voice phishing (vishing) attack.

The incident, the company told SecurityWeek, was immediately contained, the affected systems were secured, and the unauthorized access was terminated.

“The threat actor gained access to Optimizely’s systems through a sophisticated voice-phishing attack, but was unable to escalate privileges, install software, or create any backdoors in the Optimizely environment,” the company said.

Optimizely says it has no evidence of any sensitive customer data or personal information being compromised in the attack, but has proactively notified its customers of the incident.

The company said the incident did not disrupt its operations and confirmed that the attackers were able to access business contact information.

“The incident was confined to certain internal business systems including Zendesk, records in our Salesforce CRM, and a limited set of internal documents used for back-office operations,” the company said.

Optimizely has notified law enforcement of the attack and has engaged third-party cybersecurity experts and legal counsel to aid with the investigation.

“We are prioritizing transparency with our customers and partners; we have informed them of the incident and its scope and are continuing to provide updates and individual guidance to them directly,” the ad tech firm told SecurityWeek.

Optimizely did not name the threat actor behind the attack, but its description of the incident suggests that the infamous ShinyHunters extortion group might have been responsible for it.

Based in New York, Optimizely provides a digital experience platform enabling organizations to improve their websites and digital content.

It operates 21 offices worldwide, has nearly 1,500 employees, and provides services to more than 10,000 businesses, including H&M, PayPal, Toyota, Vodafone, and Zoom.

This article was published by Security Week. Please check their website for the original content.

Add new comment

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.
CAPTCHA This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
3 + 4 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.