Cyber Security News

Hackers Allegedly Selling Firewall Access to Canon Inc on Hacking Forums

Threat actors are allegedly offering root access to Canon Inc.’s internal firewall systems on underground hacking forums. 

According to security monitoring firm ThreatMon, the advertisement appeared on a popular dark web marketplace, claiming to provide administrator-level access to the Japanese camera giant’s network infrastructure.

The threat actor’s listing, verified by multiple security analysts, advertises privileged access to Canon’s internal network with root/administrator credentials to the company’s firewall systems. 

Threat Actor Offers Root Access to Canon’s Firewall

The listing explicitly identifies Canon as a Japanese multinational corporation with approximately $30 billion in annual revenue, primarily operating in the camera and imaging industry.

Advertisement appeared on darkweb (Source: ThreatMon)

With root access to firewall infrastructure, malicious actors could potentially establish persistent backdoors, conduct lateral movement across the network, or potentially launch devastating ransomware attacks.

The listing specifies the access type as “Firewall” with “Root/Administrator” privileges, indicating the potential for remote code execution and complete control over Canon’s network traffic filtering mechanisms. 

Communication with the seller is reportedly conducted via private messaging and Telegram channels, following standard operational security practices common on such forums.

With operations spanning multiple continents and a robust digital business portfolio, any compromise could potentially impact global operations.

Canon has previously experienced significant cybersecurity incidents. In 2020, the company confirmed a ransomware attack that resulted in the theft of employee data, including Social Security numbers, banking information, and other sensitive personal records.

Security experts recommend organizations implement defense-in-depth strategies, including multi-factor authentication (MFA), network segmentation, and privileged access management (PAM) solutions to mitigate similar threats. 

Regular security audits and penetration testing can identify vulnerabilities before malicious actors can exploit them.

Canon has not publicly confirmed the breach at the time of publication, and it remains unclear whether the listing represents legitimate access or a fraudulent claim. 

ThreatMon continues to monitor the situation, noting this type of access could potentially fetch tens of thousands of dollars on underground marketplaces.

Cybersecurity professionals remind organizations that firewall compromises can lead to extensive supply chain risks, as evidenced by numerous high-profile attacks targeting critical infrastructure and multinational corporations over the past several years.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago