ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

OmniVision says Cactus ransomware attack in 2023 compromised client data

California-based imaging sensors manufacturer OmniVision recently disclosed a data security incident that compromised the sensitive personal information of its clients.

 

In a data breach notice filed with state authorities of California, OmniVision said that on September 30 last year, it identified a security incident that involved threat actors encrypting certain systems connected to its internal network.

 

The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. Also, it took steps to remove the unauthorised access and notified law enforcement authorities about the same.

 

“This in-depth investigation determined that an unauthorised party took some personal information from certain systems between September 4, 2023, and September 30, 2023,” reads the notice.

 

“As a result of this incident, we have increased the number of monitoring solutions within our environment in order to detect suspicious activity and to prevent recurrence. We are also in the process of updating our security policies and procedures, migrating certain systems to cloud-based operations, and requiring additional security awareness training within our organisation,” OmniVision added.

 

On October 17, the Cactus ransomware group claimed responsibility for the ransomware attack on OmniVision and listed the company as a victim on its data leak site. The hacker group said it was in possession of classified data including passport copies, non-disclosure agreements, contracts and confidential documents.

 

 

After a failed ransom negotiation, the group published the stolen data in a ZIP archive that was available for free download.

 

While OmniVision found no evidence of the compromised information being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.

 

It has also offered two years of complimentary identity protection and credit monitoring services through IDX to all affected individuals.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543