{"id":39471,"date":"2021-02-07T10:04:09","date_gmt":"2021-02-07T10:04:09","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/"},"modified":"2021-02-07T10:04:09","modified_gmt":"2021-02-07T10:04:09","slug":"hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/","title":{"rendered":"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge"},"content":{"rendered":"<p><span data-label=\"in brief\">In brief<\/span> Email security biz Mimecast not only fell victim to the SolarWinds hackers, leading to its own customers being attacked, it is also trimming its workforce amid healthy profits.<\/p>\n<p>Last month Mimecast <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.mimecast.com\/blog\/important-security-update\/\">revealed<\/a> that one of its cryptographic certificates was purloined by the same team that <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2021\/01\/19\/fireeye_solarwinds_code\/\" rel=\"noopener noreferrer\">smuggled<\/a> a hidden backdoor into SolarWinds&#8217; Orion network monitoring software.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",button,mpu,\" data-sm=\",button,mpu,\" data-md=\",button,banner_plus,mpu\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Mimecast offers security services that plug into Microsoft 365 accounts, and someone with that certificate could therefore tap into Mimecast-Microsoft customer connections and steal information. What kind of info? Encrypted login details for Microsoft services, for instance. Here&#8217;s how Mimecast put it:<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",button,mpu_plusplus,\" data-sm=\",button,mpu_plusplus,\" data-md=\",button,mpu_plusplus,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>It added:<\/p>\n<p>A new certificate has been issued. Connections by one in ten of Mimecast&#8217;s 36,000 customers were at risk, we&#8217;re told, and fewer than 10 were specifically targeted as a result of the hack. Those clients have been alerted.<\/p>\n<p>In its <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/investors.mimecast.com\/news-releases\/news-release-details\/mimecast-announces-third-quarter-2021-financial-results\">third-quarter<\/a> financial results for its 2021 fiscal year, released this week, Mimecast announced its profits had exploded to $10.8m, up from $200,000 a year ago. It also highlighted big customer wins during the period, which spans the three calendar months to December 31. Amid all this, Mimecast will be trimming its staff by four per cent, costing it $3.7m in restructuring.<\/p>\n<p>&#8220;The company is also announcing that its Board of Directors approved a restructuring plan designed to align the company\u2019s resources with its strategy,&#8221; it said. &#8220;The restructuring plan, which includes a reduction of the company\u2019s workforce by approximately 4 per cent, will permit the company to increase investment in strategic growth areas.&#8221;<\/p>\n<div class=\"boxout\" readability=\"20.707224334601\">\n<p><b>The brain boxes at British Mensa<\/b> this week <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/mailchi.mp\/79530317806e\/an-update-from-the-mensa-chairman\">said<\/a> they have investigated claims they&#8217;ve been hacked, and while their database of high-IQ members was not broken into, the website did suffer a SNAFU. &#8220;In the interests of transparency, we can confirm that there have been two separate incidents where limited personal data of a few members and officers of Mensa has been exposed for a short period of time in the forum area of our website,&#8221; the org said in a statement. &#8220;Detail of these incidents have been passed to the Information Commissioner\u2019s Office and we are continuing to liaise with them.&#8221;<\/p>\n<p>The group&#8217;s <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.mensa.org.uk\/\">website<\/a> is down at the moment as a result of that probe, and is expected to return online early next week.<\/p>\n<p>Apropos of nothing, the name of the chairman of British Mensa? Chris <i>Leek<\/i>.<\/p>\n<\/div>\n<h3 class=\"crosshead\"> <span>Sonicwall fixes its firmware zero-day flaw<\/span><br \/>\n<\/h3>\n<p>As <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2021\/01\/23\/in_brief_security\/\" rel=\"noopener noreferrer\">we reported<\/a> last week, Sonicwall&#8217;s Secure Mobile Access (SMA) 100 Series boxes have a vulnerability that can be exploited by anyone who can reach them to hijack the gear, and now it&#8217;s time to get patching. Because patches are now available.<\/p>\n<p>&#8220;All SMA 100 series users must apply this patch IMMEDIATELY to avoid potential exploitation,&#8221; <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.sonicwall.com\/support\/product-notification\/urgent-security-notice-sonicwall-confirms-sma-100-series-10-x-zero-day-vulnerability-feb-1-2-p-m-cst\/210122173415410\/\">it warned<\/a>. If you have one of the following with firmware 10.x, you need to apply a security update: SMA 200, SMA 210, SMA 400, or SMA 410 physical boxes, or a virtual SMA 500v system on Azure, AWS, ESXi, or HyperV.<\/p>\n<p>The biz said it was alerted to the hole by security shop NCC Group on January 31. US-CERT has also <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/02\/02\/zero-day-vulnerability-sonicwall-sma-100-series-version-10x\">issued an advisory<\/a>, telling people to patch as soon as possible.<\/p>\n<div class=\"boxout\" readability=\"19.271623672231\">\n<p><b>Some Raspberry Pi<\/b> owners are a little <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.raspberrypi.org\/forums\/viewtopic.php?t=302231\">miffed<\/a> that the organization added a Microsoft package repo entry to its Debian-based operating system. The repo entry is included so that Visual Studio Code, a recommended IDE by the Pi foundation, can be installed from a single <code>apt<\/code> command. However, it also means checking for updates of any packages on a system will ping Microsoft&#8217;s servers, even if VSC isn&#8217;t installed, which some think is a step too far.<\/p>\n<p>The foundation&#8217;s staff don&#8217;t see this as a problem because it simplifies the install of the IDE. If you don&#8217;t like this arrangement, <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.cyberciti.biz\/linux-news\/heads-up-microsoft-repo-secretly-installed-on-all-raspberry-pis-linux-os\/\">here are some ways<\/a> to avoid checking Microsoft&#8217;s repo during package updates.<\/p>\n<\/div>\n<h3 class=\"crosshead\"> <span>Someone in the US military <i>really<\/i> likes Star Wars<\/span><br \/>\n<\/h3>\n<p>The research wing of the US military, DARPA, has <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.darpa.mil\/news-events\/2020-01-28\">released<\/a> the results of its reward program for vulnerability finders, dubbed the Finding Exploits to Thwart Tampering Bug Bounty, or <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2020\/06\/09\/darpa_bug_bounty\/\" rel=\"noopener noreferrer\">FETT<\/a>.<\/p>\n<p>One goal of FETT was to check the effectiveness of DARPA&#8217;s System Security Integration Through Hardware and Firmware (<a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.darpa.mil\/program\/ssith\">SSITH<\/a>) project, using a mix of their own penetration testers and independents from security org Synack. Your humble vulture think it&#8217;s safe to say the DARPA crew aren&#8217;t Trekkies.<\/p>\n<p>The three-month bounty program found 10 valid vulnerabilities in SSITH technology \u2013 a <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/fett.darpa.mil\/BugBounty\">collection of microprocessors<\/a> and software stacks from Lockheed Martin, MIT, and the like \u2013 seven of them critical and three high risk on the CVSS scale. Four have been patched, and work is underway on the rest.<\/p>\n<p>\u201cKnowing that virtually no system is unhackable, we expected to discover bugs within the processors but FETT really showed us that the SSITH technologies are quite effective at protecting against classes of common software-based hardware exploits,\u201d <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.darpa.mil\/news-events\/2020-01-28\">said<\/a> Keith Rebello, the DARPA program manager leading SSITH and FETT.<\/p>\n<p>\u201cThe majority of the bug reports did not come from exploitation of the vulnerable software applications that we provided to the researchers, but rather from our challenge to the researchers to develop any application with a vulnerability that could be exploited in contradiction with the SSITH processors\u2019 security claims. We\u2019re clearly developing hardware defenses that are raising the bar for attackers.\u201d<\/p>\n<h3 class=\"crosshead\"> <span>Beware SolusVM Debian, it might not be secure<\/span><br \/>\n<\/h3>\n<p>Linux hosting provider RackNerd <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.lowendtalk.com\/discussion\/comment\/3200428\/#Comment_3200428\">has warned<\/a> that VPS customers running the Debian 10 template provided by SolusVM may be vulnerable to potential abuse. The Los Angeles-based hosting biz has found that the Debian 10 template from the SolusVM TDN, offered as an alternative to the more onerous manual installation process, creates an unexpected user account.<\/p>\n<p>\u201cWhen SolusVM\u2019s team initially created the Debian 10 template and published it on the TDN, they failed to remove the default installation user \u2018debianuser\u2019 prior to creating the OS template based upon that installation,\u201d the firm explained in an email to affected customers. \u201cThis resulted to two users being active on VPS\u2019s deployed on this template, \u2018root\u2019 and \u2019debianuser.\u2019<\/p>\n<p>\u201dThe notice follows reports from other hosting providers like Florida-based Hosthatch that they\u2019ve detected compromised \u201c\u2019debianuser\u201d accounts in VMs running Debian from a SolusVM template. A discussion of the issue cites a Chinese <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/aoyouer.com\/posts\/server-hacked-record.html\">blog post<\/a> complaining about a similar VPS compromise at GreenCloudVPS last October that led the account to find a Monero mining program running without authorization on the \u201cdebianuser\u201d account.<\/p>\n<p>Among those discussing the vulnerability, it\u2019s been suggested that the \u201cdebianuser\u201d account has a weak default password, and may come with \u201csudo\u201d installed, itself <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2021\/01\/26\/qualys_sudo_bug\/\" rel=\"noopener noreferrer\">recently found<\/a> to be vulnerable. Plesk, which oversees SolusVM, did not immediately respond to a request for comment.<\/p>\n<h3 class=\"crosshead\"> <span>Security begins at school<\/span><br \/>\n<\/h3>\n<p>With schools suffering ever more ransomware infections as crims go after easy targets, IBM has put forward $3m <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/newsroom.ibm.com\/2021-02-04-IBM-Introduces-3-Million-in-Cybersecurity-Grants-for-Public-Schools-in-United-States-as-Attacks-on-Education-Grow\">in funding<\/a> to see if the situation can be improved.<\/p>\n<p>In December, the FBI <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2020\/12\/12\/in_brief_security\/\" rel=\"noopener noreferrer\">warned<\/a> about the increasing prevalence of attacks against schools, and so Big Blue commissioned a survey to identify where the weaknesses are. The results weren&#8217;t great: more than half of teachers haven&#8217;t had any computer security training, and 60 per cent of all staff weren&#8217;t aware of security alerts about remote learning.<\/p>\n<p>As a result Big Blue is offering six $500,000 grants to schools to get their security practices up to speed, and the program may be rolled out further based on the success or failure of the initial handouts. Schools have until March 1 to apply.<\/p>\n<h3 class=\"crosshead\"> <span>Cops can&#8217;t get into crook&#8217;s $60m BTC wallet<\/span><br \/>\n<\/h3>\n<p>A convicted fraudster who surreptitiously installed cryptomining software on people&#8217;s PCs has left German police stumped. The man has served his sentence for his crimes \u2013 a two-year stretch behind bars \u2013 and consistently refused to hand over the password for his Bitcoin wallet where it&#8217;s assumed he kept his ill-gotten gains. With Bitcoin&#8217;s current price surge, that wallet is now thought to contain more than $60m in digital cash, and the plod can&#8217;t open it.<\/p>\n<p>\u201cWe asked him but he didn\u2019t say,\u201d prosecutor Sebastian Murer <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.reuters.com\/article\/us-crypto-currency-germany-password\/police-seize-60-million-of-bitcoin-now-wheres-the-password-idINKBN2A511T\">told<\/a> Reuters on Friday. \u201cPerhaps he doesn\u2019t know.\u201d<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",button,dbutton,mpu_plus,dmpu,\" data-sm=\",button,dbutton,mpu_plus,dmpu,\" data-md=\",button,dbutton,mpu_plus,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Nevertheless, the criminal won&#8217;t be getting his Bitcoin wallet back, the local cops claim: police have seized it, and continue to try to find a way to access the funds. \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2021\/02\/07\/in_brief_security\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Plus: British Mensa in data leak blunder, DARPA are Star Wars fans, Sonicwall patch out, and more In brief\u00a0 Email security biz Mimecast not only fell victim to the SolarWinds hackers, leading to its own customers being attacked, it is also trimming its workforce amid healthy profits.\u2026  READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-39471","post","type-post","status-publish","format-standard","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-07T10:04:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge\",\"datePublished\":\"2021-02-07T10:04:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/\"},\"wordCount\":1400,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/\",\"name\":\"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"datePublished\":\"2021-02-07T10:04:09+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#primaryimage\",\"url\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"contentUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/","og_locale":"en_US","og_type":"article","og_title":"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-02-07T10:04:09+00:00","og_image":[{"url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge","datePublished":"2021-02-07T10:04:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/"},"wordCount":1400,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/","url":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/","name":"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","datePublished":"2021-02-07T10:04:09+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#primaryimage","url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","contentUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2YCAMZali14HZelk@iFePLQAAAME&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hacked-by-solarwinds-backdoor-masterminds-mimecast-now-lays-off-staff-after-profit-surge\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39471","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=39471"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39471\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=39471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=39471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=39471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}