Cognizant Technology Solutions disclosed that a ransomware attack disrupted parts of its environment and led to the likely exfiltration of a limited amount of data from company systems. The company said it discovered the intrusion on April 20, 2020, with malicious activity occurring between April 9 and April 11, and notified affected individuals that exposed information included names and one or more sensitive identifiers such as Social Security numbers, tax identification numbers, financial account details, driver’s license information, or passport information.
Reporting tied the incident to the Maze ransomware operation based on indicators of compromise associated with files previously linked to the group, although Maze operators reportedly denied responsibility in an interview cited by coverage. Cognizant said it was working with the FBI, cyber-defense firms, and customers to contain the attack, share technical details and IoCs, strengthen security, and provide affected individuals with 12 months of complimentary credit monitoring and dark web monitoring services through ID Experts.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
In a breach notification letter dated June 17, 2020, Cognizant told affected individuals that personal information including names and sensitive identifiers was impacted, said it was cooperating with the FBI, and offered 12 months of complimentary credit and dark web monitoring services.
Maze operators reportedly denied association with the Cognizant incident in an interview with Bleeping Computer, despite reporting that tied the attack to Maze.
Reporting said Cognizant shared IoCs including IP addresses tied to files previously associated with Maze, and SentinelLabs' Vitali Kremez released Yara rules related to Maze tactics, techniques, and procedures for the attack.
Cognizant confirmed it was hit by a ransomware attack that disrupted its systems and said it was providing customers with indicators of compromise and other technical details while working with external cyber-defense firms and law enforcement to contain the incident.
Cognizant said it learned on April 20, 2020 that attackers had staged and likely exfiltrated a limited amount of data from its systems.
Cognizant said the ransomware attack that disrupted its systems began on a Friday evening in April 2020.
Cognizant said the malicious activity tied to its ransomware incident occurred between April 9 and April 11, 2020, during which attackers staged and likely exfiltrated a limited amount of data.
Reporting noted that Maze operators had previously been linked to a high-profile attack against the city of Pensacola, Florida, in December 2019.
The Maze ransomware family was first discovered in 2019, establishing the malware later linked in reporting to the Cognizant incident.
The article cited a November Maze ransomware attack against Allied Universal, where attackers later demanded 300 Bitcoin and threatened misuse of stolen information after the company refused to pay.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.