FireEye says some internal systems were hacked by nation state actors, compromising its Red Team tools, used to test the defenses of its thousands of customers
The cybersecurity company said the attack compromised its software tools used to test the defenses of its thousands of customers
Wall Street Journal Dustin Volz
Context & Ripple Effects
FireEye built its reputation on naming state-sponsored operations — it has previously tied dozens of zero-day exploits to government-backed hacking — but this disclosure turns the lens on itself: nation-state actors got inside its network and took the very Red Team tools it uses to probe customer defenses. That makes the company's own arsenal a potential weapon against the thousands of clients it tests.
The timing matters because this breach became the thread that unraveled something much bigger: US officials later said the SolarWinds campaign would likely have gone undetected if not for the security alert at FireEye that triggered scrutiny. Within months, FireEye was again on the front line, reporting China-linked groups exploiting Pulse Secure VPN flaws against US defense-industry customers.
First-order effects
- FireEye's thousands of customers must now assume adversaries hold the same Red Team toolkit used to test their networks, forcing FireEye to publish countermeasures against its own tradecraft.
- FireEye faces an immediate credibility test as a defender-for-hire whose internal perimeter failed against exactly the class of attacker it sells protection from.
Second-order effects
- The intrusion's detection cascaded into the discovery of the broader SolarWinds supply-chain campaign, converting one vendor's breach into the intelligence starting point for a government-wide incident response.
- Rival security firms are pushed toward sharing offensive-tool signatures and detection guidance, since any competitor's stolen toolkit is a shared threat to every customer base.
Third-order effects
- State actors systematically targeting the defenders themselves — later seen again in the Pulse Secure VPN exploitation of defense contractors — points to security vendors becoming primary attack surface rather than trusted intermediaries.
- Incidents of this scale strengthen the case FireEye and Microsoft made at the SolarWinds hearing for mandatory breach reporting, shifting breach disclosure from voluntary choice to regulatory obligation.
The trend: Nation-state attackers are increasingly striking the security industry's own tooling and infrastructure, turning defensive vendors into both high-value targets and involuntary intelligence sources.
Related: FireEye · Red Team · Dual-use code intelligence · SolarWinds detected via FireEye alert · FireEye details global zero-day exploitation
Related Coverage
- Russia's FireEye Hack Is a Statement—but Not a Catastrophe Wired · Lily Hay Newman
- View article FireEye
- Spies with Russia's foreign intelligence service believed to have hacked a top American cybersecurity firm and stolen its sensitive tools Washington Post
- Premiere security firm FireEye says it was breached by nation-state hackers Ars Technica · Dan Goodin
- Cybersecurity Firm FireEye Says It Was Hacked By a Nation-State That Rhymes With Frussia Gizmodo · Brianna Provenzano
- Cybersecurity firm FireEye says state-sponsored hackers stole its tools Engadget · Igor Bonifacic
- Top Cyber Firm, FireEye, Says It's Been Hacked By A Foreign Govt. NPR · Greg Myre
- U.S. cybersecurity firm FireEye discloses breach, theft of internal hacking tools Reuters · Christopher Bing
- FireEye says hackers stole its red-team tools, suggests state-sponsored group is to blame CyberScoop · Sean Lyngaas
- FireEye, a Top Cybersecurity Firm, Says It Was Hacked By a Nation-State Slashdot · BeauHD
- FireEye cybersecurity tools compromised in state-sponsored attack The Verge · Jon Porter
- Cybersecurity giant FireEye hacked by nation-state, likely Russia TechSpot · Rob Thubron
- America's Top Cybersecurity Firm FireEye Hacked, FEYE Stock Tanks 8% coinspeaker.com · Bhushan Akolkar
- Cybersecurity Firm FireEye Got Hacked; Red-Team Pentest Tools Stolen The Hacker News · Ravie Lakshmanan
- Suspected Russian Attackers Steal FireEye Red Team Tools infosecurity-magazine.com · Phil Muncaster
- FireEye, a top U.S. cybersecurity company, says it was hacked NBC News
- FireEye Shares Details of Recent Cyber Attack, Actions to Protect Community FireEye · Kevin Mandia
- Theft of FireEye Red Team Tools us-cert.cisa.gov
Discussion
-
@nicoleperlroth
Nicole Perlroth
on x
NEW: FireEye, usually the first call for cyberattack victims the world over, was itself hacked. The hackers — evidence points to Russian intel— made off with their “Red Team” tools, allowing them to mount their own attacks. W/ @SangerNYT https://www.nytimes.com/...
-
@dalperovitch
Dmitri Alperovitch
on x
With the Fireeye breach news coming out, it's important to remember that no one is immune to this. Many security companies have been successfully compromised over the years, including Symantec, Trend, Kaspersky, RSA and Bit9 1/
-
@dnvolz
Dustin Volz
on x
NEW: Major cybersecurity firm FireEye has been hacked in what it says is a highly sophisticated foreign nation-state attack that compromised its Red Team tools. A person familiar with the matter said Russia is the leading suspect.
-
@dalperovitch
Dmitri Alperovitch
on x
The biggest news here for me is the admirable standard that Kevin Mandia and @Fireeye team is setting in rapid and transparent disclosure of the intrusion, as well as release of red team tools stolen by the adversary 3/
-
@dnvolz
Dustin Volz
on x
Why would Russia hack FireEye? It could be an intel goldmine. Another possible motive: payback for exposing past ops. “I wouldn't discount this as a form of retaliation,” @RidT says. “They sell security, so if they get breached it's very bad optics.” https://www.wsj.com/...
-
@x0rz
@x0rz
on x
My guess is APT29 will be hard to catch for the next few months, if not years. Given this group history, companies like FireEye are strategic targets to ensure opsec and securing their future operations https://twitter.com/... https://twitter.com/...
-
@bing_chris
Chris Bing
on x
It is unclear: -how conducted the hack -which software systems are affected -when the intrusion occurred -what the attackers motive is https://www.reuters.com/...
-
@robertmlee
Robert M. Lee
on x
Going to be a lot of folks that dunk on FireEye for this but from my quick review they found it themselves and self disclosed. Everyone gets breached. Kudos to Kevin and the team for detecting and responding well. https://twitter.com/...
-
@wylienewmark
Horkos
on x
WaPo (https://twitter.com/...) and WSJ (https://twitter.com/...) are linking (by degrees) the FEYE compromise to the SVR. While it's too early to speculate as to attribution, I will say the SVR has a history of successfully compromising hard targets - including security entities.
-
@markwarner
Mark Warner
on x
This hack demonstrates that even the most sophisticated companies are vulnerable to cyber attacks. We need to work with our allies to develop clear international norms for cyber, and agreed-upon measures to enforce them. https://twitter.com/...
-
@thegrugq
Thaddeus E. Grugq
on x
Kaspersky: https://twitter.com/... https://twitter.com/...
-
@jeremiahg
Jeremiah Grossman
on x
I wonder if at FireEye knew of the breach prior to the Blackstone investment. It was only 3 weeks ago. “FireEye Announces $400 Million Strategic Investment Led by Blackstone” https://twitter.com/...
-
@jameshohmann
James Hohmann
on x
There's a bear in the woods. 🐻 🌲 🇷🇺 https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Not the first time a major security vendor gets hacked by a nation-state RSA got hacked in 2011: https://bits.blogs.nytimes.com/ ... ...and Kaspersky in 2015: https://www.kaspersky.co.uk/ ...
-
@ericgeller
Eric Geller
on x
Here's FireEye's blog post: https://www.fireeye.com/... They say they're releasing information about how to detect their stolen cyberattack simulation tools so that the hackers can't use them.
-
@lobotc2dfw
Brent Wyrick
on x
Well F@#$ FireEye. Not good
-
@nakashimae
Ellen Nakashima
on x
BREAKING: A top cyber firm, FireEye, — was breached—likely by Russia, and its sensitive “red team” tools were stolen. Even the most sophisticated firms that protect others against hacks can be hacked. w/ @Joseph_Marks_ https://www.washingtonpost.com/ ...
-
@nakashimae
Ellen Nakashima
on x
Sources tell the WaPo that the Russian SVR intelligence service —APT 29 — appears to be behind the hack of FireEye. That's the same group that hacked Democratic servers in 2015. But the investigation continues. @Joseph_Marks_ https://www.washingtonpost.com/ ...
-
@dnvolz
Dustin Volz
on x
The FBI is also investigating. “I've concluded we are witnessing an attack by a nation with top-tier offensive capabilities,” said FireEye CEO Kevin Mandia. “The attackers tailored their world-class capabilities specifically to target and attack FireEye.” https://www.wsj.com/...
-
@jonathanmaze
Jonathan Maze
on x
This gives me all sorts of confidence in security systems. https://twitter.com/...
-
@dnvolz
Dustin Volz
on x
I'm told investigators, including U.S. intel agencies, suspect Russia's SVR—one of two groups that hacked the DNC—is likely behind the FireEye hack. All sources caution that any conclusions on attribution are preliminary. https://www.wsj.com/... https://twitter.com/...
-
@thomasareed
Thomas Reed
on x
Some FireEye competitors are likely to point and laugh. However, this is a good time to remind everyone that if a nation-state adversary wants your data, they WILL get your data. There's no defense that will keep out a sufficiently determined, resourceful attacker. https://twitte…
-
@dalperovitch
Dmitri Alperovitch
on x
Attribution of @FireEye breach to SVR, Russian civilian intelligence agency https://twitter.com/...
-
@alex
Very Tired Alex
on x
shares -7.5% $FEYE https://twitter.com/...
-
@eddiepereztx
Eddie Perez
on x
When one of the world's largest cybersecurity companies is the victim of successful hacking by a foreign nation-state, this illustrates the global threat environment for election infrastructure. “...we are witnessing an attack by a nation with top-tier offensive capabilities...” …
-
@bing_chris
Chris Bing
on x
The FBI and Microsoft are assisting with an internal investigation. FireEye has been privately working with a group of software vendors in recent weeks to share defensive measure. Mandia says no 0days were included. Hard to measure impact atm. https://www.reuters.com/...
-
@dnvolz
Dustin Volz
on x
MORE: The attack used infrastructure not previously seen in attacks elsewhere and appeared very deliberately targeted at FireEye. “This was a sniper shot that got through,” a person involved in the response said. https://www.wsj.com/...
-
@brianpkime
Brian Kime
on x
The sphincters of every security vendor CEO just got a little tighter. https://www.wsj.com/...
-
@shanvav
Shannon Vavra
on x
A state-sponsored attacker has accessed FireEye's Red Team tools, which it uses to test customer security, & primarily sought info on gov customers. FEYE is releasing ways to detect use of the stolen tools to try neutralizing hackers' attempts to use them https://www.fireeye.com/…
-
@file411
@file411
on x
Shot... ht @Kitten0409 be patience ...wait for it. . https://twitter.com/...
-
@kennwhite
Kenn White
on x
Two observations on the FireEye hack. One, they claim no 0-day exploits were stolen, just a combination of common & bespoke red team tools. Second, the GitHub repo they link to (twice) in their post has either been pulled or made private. https://www.fireeye.com/...
-
@ivanthek
@ivanthek
on x
“You Had One Job” to FireEye
-
@dnvolz
Dustin Volz
on x
People familiar with the matter said FireEye is not sure how the intrusion took place. The hacker was very interested in gov't clients, but FireEye says it has seen no evidence yet of customer data being compromised from primary systems that hold that info https://www.wsj.com/...
-
@gossithedog
Kevin Beaumont
on x
I think vendors and orgs are going to have add detection for breached FireEye offensive security tools. Good on FireEye for disclosing. https://www.fireeye.com/...
-
@iblametom
Thomas Brewster
on x
FireEye got hacked. Rut-Roh. https://twitter.com/...
-
@stevebellovin
Steven M. Bellovin
on x
For once, the “highly sophisticated” description of an attack may be accurate... https://twitter.com/...
-
@swiftonsecurity
@swiftonsecurity
on x
Oh wow this is interesting. Behavior rules to detect their own private engagement tools TTPs, also used by attackers. https://github.com/... https://twitter.com/...
-
@chey_cobb
CyberSec Chey
on x
😤 FireEye now joins the NSA and the CIA as the largest suppliers of arms to criminal cyber gangs & hostile military forces. @zcobb https://www.reuters.com/...
-
@bing_chris
Chris Bing
on x
Just added: “Plenty of similar companies have also been popped like this,” said a Western security official. https://www.reuters.com/... Sources tell Reuters that FireEye is not the only firm in recent months/weeks that's been popped and their internal hacking tools were stolen.
-
@carolleonnig
Carol Leonnig
on x
🚨 Hacking alert. Russia suspected. https://twitter.com/...
-
@journogeoffz
Geoff Ziezulewicz
on x
FireEye was also announced as the winner of the Navy's annual Artificial Intelligence Applications to Autonomous Cybersecurity Challenge on Monday: https://www.navy.mil/... https://twitter.com/...
-
@underthebreach
Alon Gal
on x
Allegedly APT 29, probably wasn't done by a phishing email similar to how they owned Podesta and the DNC in 2015.. https://twitter.com/...
-
@bing_chris
Chris Bing
on x
Big advancement in the storyline. WaPo reports the threat actor that hit FireEye is Russian intelligence. APT29 or SVR https://twitter.com/...
-
@oliverdarcy
Oliver Darcy
on x
“It was a stunning theft, akin to bank robbers who, having cleaned out local vaults, then turned around and stole the F.B.I.'s investigative tools.” https://www.nytimes.com/...
-
@malwarejake
Jake Williams
on x
This is... not good. But mad props to FireEye for disclosing and taking this action. I'm sure others would have handled things MUCH differently. Unauthorized Access of FireEye Red Team Tools | FireEye Inc https://www.fireeye.com/...
-
@evacide
Eva
on x
I don't know who needs to hear this, but if you're running a security company, you are a target for nation-state espionage. https://twitter.com/...
-
@joseph_marks_
Joseph Marks
on x
New to this story: The FireEye hack appears to be linked to Russia, according to a U.S. official familiar with the matter, who spoke on condition of anonymity to discuss a sensitive matter. https://twitter.com/...