

You’ve likely seen the headlines about 3CX suffering a supply chain attack. What you might have not seen is that 3CX was aware of alerts identifying their app as malicious seven days prior to taking any action. You can see the entire situation play out on their community forums in this thread, but here is a quick summary:
The 3CX supply chain attack made headlines — but what received less attention is that 3CX was aware of alerts identifying their app as malicious seven days before taking any action. Here is a quick summary of what happened:
- 3CX was alerted by multiple customers that their endpoint security software was flagging the 3CX desktop app as malicious.
- 3CX staff responded by incorrectly assuming these alerts were false positives. When customers asked 3CX to contact security vendors to better understand why the app was being flagged, staff was dismissive and told customers to contact the vendors themselves.
- 3CX had the opportunity to respond to this supply chain attack seven days earlier than they did — a lifetime in incident response. Alert fatigue among 3CX and their customers led to a major danger: alert indifference.
Alert indifference is best explained using the classic fable, The Boy Who Cried Wolf. In the fable, a young shepherd boy repeatedly raises false alarms of a wolf attack, causing the villagers to ignore his cries when a real wolf shows up. The false alarms caused alert fatigue, which eventually led to alert indifference when a real threat occurred.
Much like the fable, alert indifference in cybersecurity is a phenomenon where individuals or organizations, due to alert fatigue, become desensitized to security alerts and fail to take appropriate actions in response to potential threats. This can cause delayed or inadequate responses, resulting in data breaches, financial losses, and reputational damage.
So how can organizations address this issue? First, it is not enough to simply have reliable security tools in place — those tools must also be properly configured and tuned post-deployment to ensure alerts are useful and accurate. Be wary of security solutions that claim to work "out of the box." Every organization is different, and no security tool can cover the unique complexities of them all without modification.
Additionally, make sure humans are investigating alerts. While AI and machine learning have made significant strides in identifying threats, they still cannot compete with the expertise of a security analyst who has contextual knowledge of their clients' unique systems. Security teams can fortify their investigation and response by setting up proper procedures for handling alerts, including clearly defined escalation paths and incident response plans. Regular training and simulations can also help security teams improve response times and accuracy.
A security tool that cries wolf can be just as dangerous as a real cyber threat if it causes alert indifference. By implementing reliable, properly tuned security tools and ensuring real humans are handling alerts, organizations can reduce the risk of alert fatigue and keep their security teams prepared to respond to genuine threats.
Elpha Secure's unique combination of cyber insurance, endpoint software, and 24/7 SOC leverages traditional risk transfer, technology, and human intelligence to cut through the white noise and minimize alert indifference.
Send us an email
Give us a call