Saturday, January 30, 2021

The recent SolarWinds related attack is part of a larger Russian hacking campaign. While we deal with this aggressive behavior from Russia at all levels, the attack also reminds us CloudHopper, a 2016 Chinese-led espionage campaign that targets many US organizations through the cloud service providers that they use. The main attack vector was spear phishing. The cloud service providers that were attacked included Fujitsu, Tata Consultancy Services, NTT Data, Dimension Data, Computer Sciences Corporation and DXC Technology. More details can be found in this nice Reuters article: https://www.reuters.com/investigates/special-report/china-cyber-cloudhopper/