February 22, 2021
Accellion Provides Update to FTA Security Incident Following Mandiant’s Preliminary Findings
Mandiant Identifies Criminal Threat Actor and Mode of Attacks
GlobeNewswire
PALO ALTO, Calif., Feb. 22, 2021 (GLOBE NEWSWIRE) --
Accellion, Inc., provider of the industry’s first enterprise content firewall, today issued a statement regarding Mandiant’s preliminary findings with regards to the previously reported cyberattacks on Accellion’s legacy FTA product.
Mandiant, a division of FireEye, Inc., has identified UNC2546 as the criminal hacker behind the cyberattacks and data theft involving Accellion’s legacy File Transfer Appliance product. Multiple Accellion FTA customers who have been attacked by UNC2546 have received extortion emails threatening to publish stolen data on the “CL0P^_- LEAKS" .onion website. Some of the published victim data appears to have been stolen using the DEWMODE web shell. Mandiant is tracking the subsequent extortion activity under a separate threat cluster, UNC2582.