Skip to main content

Mimecast says SolarWinds hackers breached its network and spied on customers


Mimecast-issued certificate used to connect to customers’ Microsoft 365 tenants.

DAN GOODIN - 3/16/2021


Email-management provider Mimecast has confirmed that a network intrusion used to spy on its customers was conducted by the same advanced hackers responsible for the SolarWinds supply chain attack.


The hackers, which US intelligence agencies have said likely have Russian origins, used a backdoored update for SolarWinds Orion software to target a small number of Mimecast customers. Exploiting the Sunburst malware sneaked into the update, the attackers first gained access to part of the Mimecast production-grid environment. They then accessed a Mimecast-issued certificate that some customers use to authenticate various Microsoft 365 Exchange web services.


Full Article.

0 replies

Be the first to reply!
