/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FireEye says some internal systems were hacked by nation state actors, compromising its Red Team tools, used to test the defenses of its thousands of customers

The cybersecurity company said the attack compromised its software tools used to test the defenses of its thousands of customers

Wall Street Journal Dustin Volz

Context & Ripple Effects

FireEye built its reputation on naming state-sponsored operations — it has previously tied dozens of zero-day exploits to government-backed hacking — but this disclosure turns the lens on itself: nation-state actors got inside its network and took the very Red Team tools it uses to probe customer defenses. That makes the company's own arsenal a potential weapon against the thousands of clients it tests.

The timing matters because this breach became the thread that unraveled something much bigger: US officials later said the SolarWinds campaign would likely have gone undetected if not for the security alert at FireEye that triggered scrutiny. Within months, FireEye was again on the front line, reporting China-linked groups exploiting Pulse Secure VPN flaws against US defense-industry customers.

First-order effects

  • FireEye's thousands of customers must now assume adversaries hold the same Red Team toolkit used to test their networks, forcing FireEye to publish countermeasures against its own tradecraft.
  • FireEye faces an immediate credibility test as a defender-for-hire whose internal perimeter failed against exactly the class of attacker it sells protection from.

Second-order effects

  • The intrusion's detection cascaded into the discovery of the broader SolarWinds supply-chain campaign, converting one vendor's breach into the intelligence starting point for a government-wide incident response.
  • Rival security firms are pushed toward sharing offensive-tool signatures and detection guidance, since any competitor's stolen toolkit is a shared threat to every customer base.

Third-order effects

  • State actors systematically targeting the defenders themselves — later seen again in the Pulse Secure VPN exploitation of defense contractors — points to security vendors becoming primary attack surface rather than trusted intermediaries.
  • Incidents of this scale strengthen the case FireEye and Microsoft made at the SolarWinds hearing for mandatory breach reporting, shifting breach disclosure from voluntary choice to regulatory obligation.

The trend: Nation-state attackers are increasingly striking the security industry's own tooling and infrastructure, turning defensive vendors into both high-value targets and involuntary intelligence sources.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    NEW: FireEye, usually the first call for cyberattack victims the world over, was itself hacked. The hackers — evidence points to Russian intel— made off with their “Red Team” tools, allowing them to mount their own attacks. W/ @SangerNYT https://www.nytimes.com/...
  • @dalperovitch Dmitri Alperovitch on x
    With the Fireeye breach news coming out, it's important to remember that no one is immune to this. Many security companies have been successfully compromised over the years, including Symantec, Trend, Kaspersky, RSA and Bit9 1/
  • @dnvolz Dustin Volz on x
    NEW: Major cybersecurity firm FireEye has been hacked in what it says is a highly sophisticated foreign nation-state attack that compromised its Red Team tools. A person familiar with the matter said Russia is the leading suspect.
  • @dalperovitch Dmitri Alperovitch on x
    The biggest news here for me is the admirable standard that Kevin Mandia and @Fireeye team is setting in rapid and transparent disclosure of the intrusion, as well as release of red team tools stolen by the adversary 3/
  • @dnvolz Dustin Volz on x
    Why would Russia hack FireEye? It could be an intel goldmine. Another possible motive: payback for exposing past ops. “I wouldn't discount this as a form of retaliation,” @RidT says. “They sell security, so if they get breached it's very bad optics.” https://www.wsj.com/...
  • @x0rz @x0rz on x
    My guess is APT29 will be hard to catch for the next few months, if not years. Given this group history, companies like FireEye are strategic targets to ensure opsec and securing their future operations https://twitter.com/... https://twitter.com/...
  • @bing_chris Chris Bing on x
    It is unclear: -how conducted the hack -which software systems are affected -when the intrusion occurred -what the attackers motive is https://www.reuters.com/...
  • @robertmlee Robert M. Lee on x
    Going to be a lot of folks that dunk on FireEye for this but from my quick review they found it themselves and self disclosed. Everyone gets breached. Kudos to Kevin and the team for detecting and responding well. https://twitter.com/...
  • @wylienewmark Horkos on x
    WaPo (https://twitter.com/...) and WSJ (https://twitter.com/...) are linking (by degrees) the FEYE compromise to the SVR. While it's too early to speculate as to attribution, I will say the SVR has a history of successfully compromising hard targets - including security entities.
  • @markwarner Mark Warner on x
    This hack demonstrates that even the most sophisticated companies are vulnerable to cyber attacks. We need to work with our allies to develop clear international norms for cyber, and agreed-upon measures to enforce them. https://twitter.com/...
  • @thegrugq Thaddeus E. Grugq on x
    Kaspersky: https://twitter.com/... https://twitter.com/...
  • @jeremiahg Jeremiah Grossman on x
    I wonder if at FireEye knew of the breach prior to the Blackstone investment. It was only 3 weeks ago. “FireEye Announces $400 Million Strategic Investment Led by Blackstone” https://twitter.com/...
  • @jameshohmann James Hohmann on x
    There's a bear in the woods. 🐻 🌲 🇷🇺 https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Not the first time a major security vendor gets hacked by a nation-state RSA got hacked in 2011: https://bits.blogs.nytimes.com/ ... ...and Kaspersky in 2015: https://www.kaspersky.co.uk/ ...
  • @ericgeller Eric Geller on x
    Here's FireEye's blog post: https://www.fireeye.com/... They say they're releasing information about how to detect their stolen cyberattack simulation tools so that the hackers can't use them.
  • @lobotc2dfw Brent Wyrick on x
    Well F@#$ FireEye. Not good
  • @nakashimae Ellen Nakashima on x
    BREAKING: A top cyber firm, FireEye, — was breached—likely by Russia, and its sensitive “red team” tools were stolen. Even the most sophisticated firms that protect others against hacks can be hacked. w/ @Joseph_Marks_ https://www.washingtonpost.com/ ...
  • @nakashimae Ellen Nakashima on x
    Sources tell the WaPo that the Russian SVR intelligence service —APT 29 — appears to be behind the hack of FireEye. That's the same group that hacked Democratic servers in 2015. But the investigation continues. @Joseph_Marks_ https://www.washingtonpost.com/ ...
  • @dnvolz Dustin Volz on x
    The FBI is also investigating. “I've concluded we are witnessing an attack by a nation with top-tier offensive capabilities,” said FireEye CEO Kevin Mandia. “The attackers tailored their world-class capabilities specifically to target and attack FireEye.” https://www.wsj.com/...
  • @jonathanmaze Jonathan Maze on x
    This gives me all sorts of confidence in security systems. https://twitter.com/...
  • @dnvolz Dustin Volz on x
    I'm told investigators, including U.S. intel agencies, suspect Russia's SVR—one of two groups that hacked the DNC—is likely behind the FireEye hack. All sources caution that any conclusions on attribution are preliminary. https://www.wsj.com/... https://twitter.com/...
  • @thomasareed Thomas Reed on x
    Some FireEye competitors are likely to point and laugh. However, this is a good time to remind everyone that if a nation-state adversary wants your data, they WILL get your data. There's no defense that will keep out a sufficiently determined, resourceful attacker. https://twitte…
  • @dalperovitch Dmitri Alperovitch on x
    Attribution of @FireEye breach to SVR, Russian civilian intelligence agency https://twitter.com/...
  • @alex Very Tired Alex on x
    shares -7.5% $FEYE https://twitter.com/...
  • @eddiepereztx Eddie Perez on x
    When one of the world's largest cybersecurity companies is the victim of successful hacking by a foreign nation-state, this illustrates the global threat environment for election infrastructure. “...we are witnessing an attack by a nation with top-tier offensive capabilities...” …
  • @bing_chris Chris Bing on x
    The FBI and Microsoft are assisting with an internal investigation. FireEye has been privately working with a group of software vendors in recent weeks to share defensive measure. Mandia says no 0days were included. Hard to measure impact atm. https://www.reuters.com/...
  • @dnvolz Dustin Volz on x
    MORE: The attack used infrastructure not previously seen in attacks elsewhere and appeared very deliberately targeted at FireEye. “This was a sniper shot that got through,” a person involved in the response said. https://www.wsj.com/...
  • @brianpkime Brian Kime on x
    The sphincters of every security vendor CEO just got a little tighter. https://www.wsj.com/...
  • @shanvav Shannon Vavra on x
    A state-sponsored attacker has accessed FireEye's Red Team tools, which it uses to test customer security, & primarily sought info on gov customers. FEYE is releasing ways to detect use of the stolen tools to try neutralizing hackers' attempts to use them https://www.fireeye.com/…
  • @file411 @file411 on x
    Shot... ht @Kitten0409 be patience ...wait for it. . https://twitter.com/...
  • @kennwhite Kenn White on x
    Two observations on the FireEye hack. One, they claim no 0-day exploits were stolen, just a combination of common & bespoke red team tools. Second, the GitHub repo they link to (twice) in their post has either been pulled or made private. https://www.fireeye.com/...
  • @ivanthek @ivanthek on x
    “You Had One Job” to FireEye
  • @dnvolz Dustin Volz on x
    People familiar with the matter said FireEye is not sure how the intrusion took place. The hacker was very interested in gov't clients, but FireEye says it has seen no evidence yet of customer data being compromised from primary systems that hold that info https://www.wsj.com/...
  • @gossithedog Kevin Beaumont on x
    I think vendors and orgs are going to have add detection for breached FireEye offensive security tools. Good on FireEye for disclosing. https://www.fireeye.com/...
  • @iblametom Thomas Brewster on x
    FireEye got hacked. Rut-Roh. https://twitter.com/...
  • @stevebellovin Steven M. Bellovin on x
    For once, the “highly sophisticated” description of an attack may be accurate... https://twitter.com/...
  • @swiftonsecurity @swiftonsecurity on x
    Oh wow this is interesting. Behavior rules to detect their own private engagement tools TTPs, also used by attackers. https://github.com/... https://twitter.com/...
  • @chey_cobb CyberSec Chey on x
    😤 FireEye now joins the NSA and the CIA as the largest suppliers of arms to criminal cyber gangs & hostile military forces. ⁦@zcobb⁩ https://www.reuters.com/...
  • @bing_chris Chris Bing on x
    Just added: “Plenty of similar companies have also been popped like this,” said a Western security official. https://www.reuters.com/... Sources tell Reuters that FireEye is not the only firm in recent months/weeks that's been popped and their internal hacking tools were stolen.
  • @carolleonnig Carol Leonnig on x
    🚨 Hacking alert. Russia suspected. https://twitter.com/...
  • @journogeoffz Geoff Ziezulewicz on x
    FireEye was also announced as the winner of the Navy's annual Artificial Intelligence Applications to Autonomous Cybersecurity Challenge on Monday: https://www.navy.mil/... https://twitter.com/...
  • @underthebreach Alon Gal on x
    Allegedly APT 29, probably wasn't done by a phishing email similar to how they owned Podesta and the DNC in 2015.. https://twitter.com/...
  • @bing_chris Chris Bing on x
    Big advancement in the storyline. WaPo reports the threat actor that hit FireEye is Russian intelligence. APT29 or SVR https://twitter.com/...
  • @oliverdarcy Oliver Darcy on x
    “It was a stunning theft, akin to bank robbers who, having cleaned out local vaults, then turned around and stole the F.B.I.'s investigative tools.” https://www.nytimes.com/...
  • @malwarejake Jake Williams on x
    This is... not good. But mad props to FireEye for disclosing and taking this action. I'm sure others would have handled things MUCH differently. Unauthorized Access of FireEye Red Team Tools | FireEye Inc https://www.fireeye.com/...
  • @evacide Eva on x
    I don't know who needs to hear this, but if you're running a security company, you are a target for nation-state espionage. https://twitter.com/...
  • @joseph_marks_ Joseph Marks on x
    New to this story: The FireEye hack appears to be linked to Russia, according to a U.S. official familiar with the matter, who spoke on condition of anonymity to discuss a sensitive matter. https://twitter.com/...