Mimecast confirms it was hit by SolarWinds hackers

Hacker Typing
(Image credit: Shutterstock)

Yet another organization has announced that it has been affected by the SolarWinds hack, after email security firm Mimecast confirmed itself among the victims. 

The company noted that the threat actors accessed account credentials held by certain customers based in the US and UK.

Mimecast added that it was not aware of the stolen credentials being decrypted or misused but is advising customers located in the affected countries to reset their credentials as a precautionary step.

The fallout continues

“As we previously shared, when Microsoft informed us about the compromise of a Mimecast-issued certificate used to authenticate a subset of Mimecast’s products, we advised affected customers to break and re-establish their connections with newly issued keys,” the Mimecast blog read

“The vast majority of these customers have taken this action, and Microsoft has now disabled use of the former connection keys for all affected Mimecast customers. We also launched an internal investigation, supported by leading third-party forensics experts, and we are coordinating our activities with law enforcement. Our investigation has now confirmed that this incident is related to the SolarWinds Orion software compromise and was perpetrated by the same sophisticated threat actor.”

Mimecast was initially informed that it may have been targeted by the SolarWinds hackers by Microsoft, after the Redmond-based firm noticed that some of its self-issued authentication certificates were compromised. Around 10% of Mimecast’s customers are believed to be affected.

Mimecast can at least take some small comfort from the fact that it is far from the only firm to be targeted by the SolarWinds hackers. Among the higher-profile victims, Malwarebytes, FireEye, and Microsoft have all been impacted.

The SolarWinds breach was first discovered late last year and affected organizations based all over the world. It is unlikely that the admission from Mimecast will be the end of the SolarWinds story.

Via Bleeping Computer

TOPICS
Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A pair of hands using a keyboard
Microsoft SharePoint hijacked to spread Havoc malware
Latest in News
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence
iPad Air M3
Apple updates iPad Air with powerful M3 chip and pairs it with Pro-level Magic Keyboard
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 might improve on its predecessor in one crucial way
Nvidia RTX 5070 Founders Edition GPU shown against a green and black backdrop
Nvidia RTX 5070 early pricing hints at plenty of GPUs at the MSRP – but I’ll believe it when I see it
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop