Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On April 11, 2024, CISA urged Sisense customers to reset credentials and secrets that may have been exposed to, or used to access, Sisense services; investigate suspicious activity involving them; and report suspicious activity to CISA. The alert did not publicly detail how the compromise happened. A longer list of credentials to rotate appeared in a customer message attributed to Sisense’s CISO and reproduced by Krebs on Security—not in CISA’s brief alert.

What did CISA ask Sisense customers to do?

CISA said it was working with private-industry partners in response to a recent compromise affecting Sisense. The agency’s reported recommendation was: “Reset credentials and secrets potentially exposed to, or used to access, Sisense services.” It also urged customers to investigate suspicious activity involving those credentials and report suspicious activity to CISA. The warning was issued April 11, 2024; contemporaneous reporting said the exact nature of the incident was not clear at the time. CISA’s alert and TechCrunch’s April 11, 2024 report provide the public warning and its context.

Which credentials should customers review and rotate?

A customer message attributed to Sisense Chief Information Security Officer Sangram Dash and reproduced by Krebs on Security says customers must reset keys, tokens, and other credentials in their environment used within the Sisense application. Its inventory goes beyond a Sisense user password:

  • Sisense-related passwords, application secrets, and passwords for application users.
  • SSO JWT shared secrets, SAML certificates, and OpenID client secrets.
  • Database credentials, data-model connection strings, and user parameters.
  • Active Directory or LDAP authorization credentials.
  • Git HTTP credentials, B2D connection settings, and infusion app keys.
  • Web access tokens and custom email server credentials.
  • Secrets stored in custom code notebooks.

The message also instructed customers to log users out after applicable updates. This credential inventory is attributed to the company message reproduced by Krebs; it should not be mistaken for a checklist published in CISA’s short alert.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can an organization rotate credentials without breaking integrations?

The practical challenge is to replace each credential wherever it is stored and used, not merely change a password in one system. The company message’s broad inventory implies that administrators should map active Sisense integrations, coordinate replacement values with the connected service, and check that dependent workflows still work. These are implementation steps inferred from the credential types listed in the message, not separate CISA instructions.

  1. Inventory usage: Identify which listed credential types are actually in use, where each value is stored, and which Sisense features or connected systems depend on it.
  2. Coordinate each replacement: Arrange the new value with the relevant system owner. Update both the source and the Sisense configuration as required so the two ends of a connection remain in sync.
  3. Validate the change: Check that affected integrations and workflows still authenticate and operate after the update. Plan changes with the administrators and security staff responsible for those services.
  4. Apply the stated logout step: For applicable updates, follow the company message’s instruction to log users out.
  5. Investigate and report: Review suspicious activity involving potentially exposed credentials and report suspicious activity to CISA, as the agency urged.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is publicly established about the intrusion?

The CISA warning, as reported at the time, established that the agency was responding with industry partners to a compromise affecting Sisense and was advising customers to reset credentials, investigate, and report suspicious activity. TechCrunch reported that the exact nature of the incident was unclear on April 11, 2024.

Krebs on Security later reported, citing two confidential sources familiar with the investigation, that attackers accessed Sisense’s self-managed GitLab repository and found a token or credential that could access Sisense Amazon S3 buckets. Krebs also attributed claims about copied customer data and exposed tokens and passwords to those sources. Those details are reported allegations, not publicly established official findings in the materials cited here.

Sisense published an update titled “More on the April 2024 Security Incident.” Its existence should not be taken to mean that the company confirmed every technical detail reported elsewhere. The available sources do not establish a definitive final count of affected organizations or a final closure status. They also do not determine the present condition of any particular customer environment. Read Sisense’s incident update for the company’s own statements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.