A $1.2B sale of its products business split FireEye from Mandiant after its breach helped expose the SolarWinds supply-chain campaign.
Who they are
FireEye appears in coverage as a cybersecurity company whose threat research, incident disclosures and defensive tools shape investigations into state-linked hacking and coordinated online influence operations. Its work surfaces in stories involving SolarWinds, Microsoft, Pulse Secure, Facebook and Google, while its Mandiant digital-forensics arm became central to its 2021 corporate split.
The recent arc
Coverage intensified in late 2020 and early 2021 as FireEye moved from investigator to victim and public source on the SolarWinds incident. Its December 2020 disclosure that nation-state actors had accessed internal systems and taken Red Team tools prompted scrutiny that, according to U.S. officials cited in coverage, helped uncover the wider SolarWinds hacking campaign. FireEye then published guidance on UNC2452/SUNBURST techniques, released the open-source Azure AD Investigator, and joined Microsoft in calling for mandatory breach-reporting rules at a SolarWinds hearing. Reports also linked the intrusion to the suspected Russian APT29 group, though attribution was presented as sourced reporting rather than a confirmed FireEye finding.
The story then broadened beyond SolarWinds. In April 2021, FireEye and Pulse Secure said China-linked groups had exploited a Pulse Secure VPN flaw against U.S. defense-industry customers; by September, its researchers were tied to reporting on China-linked social-media accounts attempting to encourage anti-Asian-racism protests. June brought a strategic break: FireEye agreed to sell its products business to Symphony Technology Group for $1.2B, separating that operation from Mandiant.
The tension
The coverage centers on the difficulty of defending against state-linked campaigns that cross enterprise software, cloud identity systems, VPNs and social platforms. FireEye is both a detector of those campaigns and a target of them: Russian-linked actors were suspected in its own breach, while its research implicated China- and Iran-linked activity. That dual role also places it alongside, rather than simply against, firms such as Microsoft, Pulse Secure, Facebook and Google as they respond to shared threats.
Why it matters
If this trajectory holds, the separation of FireEye's products business from Mandiant could sharpen the distinction between selling security tools and conducting high-profile incident response and threat intelligence. The SolarWinds episode showed how a disclosure by one security company can trigger broader scrutiny across government and industry, while the Pulse Secure and social-platform cases show that the same investigative capability is relevant across several attack surfaces. Whether the split strengthens that role depends on how the newly separated businesses operate and cooperate after the transaction.
Related: SolarWinds · Microsoft · China · Russian · Facebook · Source: Treasury's hackers used a flaw in a SolarWinds product; SolarW
FireEye has appeared in 59 articles since 2015-02.
Coverage peaked in 2020Q4 with 7 articles.
Frequently mentioned alongside Chinese, Russian, SolarWinds, China.