CSIDB logo
Incident

Frost & Sullivan

Incident posture

Attack window
Jun 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Frost & Sullivan
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A business consulting firm experienced a breach when an unsecured backup directory on a public-facing server exposed confidential data, which was subsequently advertised for sale on a hacking forum by the KelvinSecurity Team. The compromised information included approximately 6,000 customer records containing names, email addresses, and company contacts, alongside 6,146 employee records with more sensitive details such as login credentials and hashed passwords. The attackers claimed they attempted to notify the organization without success before listing the data, though they asserted no actual sale occurred, intending instead to prompt remediation. The exposed backup folder was later secured, preventing further unauthorized access.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 24, 2020, cybersecurity reports revealed that business consulting firm Frost & Sullivan suffered a data breach involving unauthorized access to sensitive company databases. The incident stemmed from an unsecured backup directory on one of the organization’s public-facing servers, which contained employee and customer records alongside other confidential information. A group identifying itself as KelvinSecurity Team claimed responsibility, advertising the sale of 6,000 customer records and 6,146 company records on a hacker forum. The customer database included non-sensitive details such as client names, email addresses, company contacts, and confidentiality status indicators. The employee database contained more sensitive information, including first and last names, login credentials, email addresses, and hashed passwords. KelvinSecurity described themselves as "Business Intelligence Contractors," though external cybersecurity reports characterized them as a group engaged in illicit activities.

The attackers stated they attempted to contact Frost & Sullivan about the exposed data but received no response, prompting them to list the databases for sale as a method to alert the company. They later clarified they had not actually sold the data and hoped to initiate contact to resolve the issue. Cybersecurity firm Cyble Inc confirmed the backup folder was no longer publicly accessible after the exposure was reported. Frost & Sullivan did not publicly acknowledge the breach or respond to media inquiries regarding the incident. The breach exposed vulnerabilities in the firm’s data storage practices, particularly the misconfiguration of backup directories on internet-facing infrastructure. No further details about containment measures, forensic investigations, or direct impacts on affected individuals were disclosed in available reports.

Sources

Sources available to members: 1 source.

CSIDB