Nation-State Hackers Breach Cybersecurity Firm
Sophisticated hackers have turned the tables on FireEye, one of the world’s leading cybersecurity companies, stealing digital tools that it works by using to test its customers’ cyber defenses.
The New York Periods reported the “stunning theft,” which FireEye disclosed on Tuesday, was “akin to bank robbers who, possessing cleaned out community vaults, then turned all over and stole the FBI’s investigative tools.”
“The hack of a leading cybersecurity company demonstrates that even the most sophisticated organizations are susceptible to cyberattacks,” reported Sen. Mark Warner, the rating Democrat on the Senate Intelligence Committee.
FireEye CEO Kevin Mandia reported in a site publish that the corporation believes the attackers had been sponsored by “a country with major-tier offensive capabilities” and utilized “a novel combination of techniques not witnessed by us or our associates in the past” to entry “certain Pink Staff evaluation tools that we use to test our customers’ protection.”
“Consistent with a country-condition cyber-espionage hard work, the attacker largely sought details associated to particular federal government consumers,” he claimed.
According to the Periods, FireEye “has been the initially contact for federal government organizations and organizations all over the globe who have been hacked by the most sophisticated attackers, or panic they could possibly be.”
The firm’s Pink Staff tools mimic the behavior of numerous cyber danger actors and enable FireEye to offer diagnostic protection expert services to its consumers. The hack was the largest recognized theft of cybersecurity tools due to the fact a team termed ShadowBrokers attacked the National Protection Company in 2006.
Experts reported the thieves could use the Pink Staff tools to disguise their personal tracks when they launch foreseeable future attacks. But Mandia reported FireEye had noticed no proof to date that any attacker has utilized them.
“We have figured out and continue to master additional about our adversaries as a end result of this attack,” he reported.
Mike Chapple, a cybersecurity skilled at the University of Notre Dame and a former National Protection Company formal, termed the FireEye breach “an terribly significant attack.”
“As one of the world’s go-to cybersecurity companies, FireEye has a ringside seat for some of the most sophisticated breaches carried out globally,” he instructed CNN Enterprise.
