// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

Cisco

DISCLOSED 2026-09-13 · UNKNOWN

China-linked threat actor Fire Ant compromised Cisco IOS XR routers, management hosts, and authentication systems. The attackers created covert paths into other networks. The method of initial access is not disclosed.

The record

What we know

Disclosed
2026-09-13
Sector
technology
Country
US
Domain
cisco.com
ENDPOINT INVOLVED
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

A positive-security model might have prevented unauthorized changes to router configurations if it could enforce allowlisting on network devices, but the text does not specify how the compromise occurred, so the effectiveness is unclear.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

This page is the permanent ColdRecon entry for the Cisco disclosure. It updates if new public reporting emerges. All tracked breaches →

Cisco just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →