<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Security Breach: It Could Happen to You

Editor's note, October 2026: This article was first published in December 2020 as the first part of our Security Breach series. The cybersecurity firm in question was FireEye, which disclosed on 8 December 2020 that its red team tools had been stolen and published countermeasures so defenders could detect them. While investigating its own breach, FireEye uncovered the SolarWinds Orion supply chain compromise, which became public on 13 December 2020. We followed up in Security Breach: Following Up 30 Days Later and Security Breach: Patch or Clash. CISA closed its emergency directive on SolarWinds Orion (ED 21-01) in January 2026, as the required actions had been implemented or are now covered by Binding Operational Directive 22-01. Today, CISA's Known Exploited Vulnerabilities (KEV) catalog is the reference for which vulnerabilities attackers actually exploit.

This past week, a leading cybersecurity firm announced that its systems had been compromised by a highly sophisticated state-sponsored adversary.

What was stolen

Many cybersecurity firms have teams that try to infiltrate customer networks under controlled conditions, mimicking a potential adversary's attack. This type of work, called penetration testing or "pen testing", is common in the industry. For these operations, security firms develop many tools to identify and exploit vulnerabilities in client networks. In this breach, these tools were stolen.

Even though the breach did not release new exploits, it still creates new risk. Most breaches are caused by lapses in basic security controls, exactly what these tools are designed to detect and exploit. Pen tests reveal vulnerabilities that customers might otherwise miss, even those who run regular vulnerability scans. Unfortunately, freely available toolkits online already allow threat actors to conduct similar operations.

What should you do?

All organizations should review their security programs to make sure they have a strong security posture, with patches applied regularly. They should also review their contracts with vendors to determine what warranties, if any, are made regarding cybersecurity and incident response. Finally, organizations should make sure their incident response plans cover data breaches, since even the most sophisticated cybersecurity companies can fall victim to one.

One thing to take away from this news: if a major cybersecurity firm can be breached, anyone can. Last week, the NSA also released a cybersecurity advisory warning that Russian state-sponsored actors were exploiting a vulnerability in VMware Workspace ONE Access (CVE-2020-4006) using compromised credentials. Other organizations should take this as an opportunity to review their security posture and take immediate steps to protect themselves. If businesses prioritize security and follow best practices from the start, a breach becomes less likely and recovery from it less frantic. What that recovery can look like after a ransomware attack is covered in Post-Ransomware Recovery: What Do I Do Now?

Want to check your own security posture? Our team supports endpoint security projects, including incident response planning, and ISEC7 SPHERE monitors patch levels and known vulnerabilities of the connected systems. If you have questions about how a security breach could affect you, contact us.