Top Cybersecurity Firm FireEye Admits Nation-State Hack
FireEye reveals that a highly sophisticated, nation-state-backed hacker has breached its network and stolen its offensive red team tools. The company shares countermeasures to prevent the stolen tools from causing widespread damage.
FireEye, a leading cybersecurity company normally called in to investigate major cyberattacks, admits that it suffers a breach by a highly sophisticated, nation-state-backed threat actor. Chief executive Kevin Mandia reveals that the hackers use a novel combination of techniques to steal the company's offensive red team tools, which FireEye typically uses to find vulnerabilities in customer networks before malicious hackers do.
The stolen tools mimic the behavior of many cyberthreat actors and do not contain zero-day exploits, but they still pose a significant risk if weaponized by other hackers. Mandia compares this incident to the 2017 NSA leak that fueled the devastating WannaCry ransomware attack, though FireEye currently sees no evidence that its stolen tools are abused in the wild.
In response to the breach, FireEye proactively releases hundreds of countermeasures to help the broader cybersecurity community detect and block the use of its stolen tools. The exact timing of the breach remains unclear, but the hackers appear to target information related to FireEye's government customers, causing the company's stock to drop more than seven percent in after-hours trading.