Security

Google’s Mandiant: cybersecurity company’s X account hacked

Google's Mandiant: cybersecurity company's X account hacked

The cybersecurity company owned by Googleknown as Mandiantspent several hours trying to regain control of his account on X after this was sensationally hacked.

Yesterday, in fact, an unspecified cybercriminal took over the account, spreading a message through it. malicious links. The cyber criminal, apparently, once he obtained access to the profile, used it to pretend to be a company offering services crypto wallets. By advertising a phantom competition with prizes in tokenthe account was therefore exploited to direct the unfortunate victims towards a Malicious website.

Mandiant officials directly commented on what happened and published the following note: “We are aware of the incident impacting your Mandiant X account and are working to resolve the issue” then adding “We have regained control of the account and are currently working to restore it“.

Despite this, the hacker’s modus operandi has not yet been revealed.

How did the hacker act to get hold of Mandiant’s X profile?

After using the account to promote the malicious website, the hacker posted a cryptic and disturbing message “Check your bookmarks when you get your account back“, then mocking Mandiant with the message “Change password, please“.

All of this is quite sensational, given that we are talking about one of the main cybersecurity companies in the world. Its recent past demonstrates the importance of Mandiant in this sector: in 2022, in fact, the company was purchased by Google for 5.4 billion dollars.

Regarding the hacking case, many are currently wondering what the breach was exploited by the cybercriminal for this effective coup. The account was actually protected by a complex password and by a system of two-factor authentication?

In all likelihood, Mandiant will clarify things in the next few days by revealing what really happened to their X account.

Source: arstechnica.com

Leave a Reply

Your email address will not be published. Required fields are marked *