Top-Tier Nation-State Hackers Breach Cybersecurity Firm FireEye, Steal Red Team Tools
FireEye reveals that sophisticated nation-state hackers, widely believed to be aligned with Russia, breach their systems and steal specialized offensive security tools. The company sees no evidence yet that the stolen red team tools are being used in the wild.
Cybersecurity firm FireEye announces that it suffers a major breach, losing specialized red team tools that it uses to test customer defenses and find potential vulnerabilities. The company's stock drops nearly 10 percent in extended trading as investors react to the startling news of an attack on one of the industry's most respected players.
CEO Kevin Mandia states that a nation with top-tier offensive capabilities targets FireEye specifically, tailoring their methods to bypass security measures like two-factor authentication. Investigators familiar with the incident point to hackers closely aligned with the Russian government, noting that the attackers operate from two dozen previously unseen IP addresses based in the United States.
Despite the theft of these powerful diagnostic security tools, FireEye finds no evidence that anyone uses them in a cyber-attack. Experts call the breach extraordinarily significant because FireEye holds a ringside seat to the world's most sophisticated threats and maintains one of the most complete collections of cyberwarfare tools for defensive work.