Header image

Rubrik Reports 'Unauthorised Actor' Access Log Files

No evidence of unauthorised access to any data or internal code.

Rubik has said that an “unauthorised actor” accessed a small number of log files in what it calls “anomalous activity on a server.”

In a statement from co-founder and CTO Arvind Nithrakashyap, and CISO Michael Mestrovich, they said the Rubrik Information Security Team recently discovered anomalous activity on a server that contained log files. “We promptly took the server offline to mitigate the risk” and an investigation confirmed that the incident was isolated to this one server.

“We found no evidence of unauthorised access to any data we secure on behalf of our customers, or our internal code.”

Unauthorised Actor

Rubrik did claim that through its investigation, it discovered that an “unauthorised actor” accessed a small number of log files, most of which contained non-sensitive information.

Whilst one file contained some limited access information, it rotated keys to mitigate any residual risk, “even though we found no evidence that access information was misused.”

The statement said: “We would like to reiterate that after a detailed analysis with the third party partner, we have found no evidence of unauthorised access to any data we secure on behalf of our customers or our internal code.

“We take the security of our customers as well as our own systems extremely seriously and while the issue has been fully mitigated, we felt it was important to be transparent about this to all our customers, partners and prospects.”

Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Dan Raywood
Dan Raywood Senior Editor SC Media UK

Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.

Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.

Upcoming Events

02
Apr
Webinar

Benchmarking Security Skills and How to Ensure Secure-by-Design in the Enterprise

Consider how to prove the return on investment when implementing a secure-by-design initiative

image image image