![]() | |
Formerly | Red Cliff Consulting (2004–2006) |
---|---|
Type | Subsidiary |
Industry | Information security |
Founded | 2004 |
Founder | Kevin Mandia |
Headquarters | Reston, Virginia, U.S. |
Key people | Kevin Mandia, CEO |
Revenue | ![]() |
Number of employees | 2,335 (December 2021) |
Parent | |
Website | mandiant |
Footnotes /references [1] |
Mandiant is an American cybersecurity firm and a subsidiary of Google. It rose to prominence in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireEye for $1 billion, who eventually sold the FireEye product line, name, and its employees to Symphony Technology Group for $1.2 billion in June 2021.
In March 2022, Google announced that it would acquire the company for $5.4 billion and integrate it into its Google Cloud division, with the firm becoming fully incorporated in September 2022.
Kevin Mandia, a former United States Air Force officer who serves as the company's chief executive officer, founded Mandiant as Red Cliff Consulting in 2004 before rebranding to its current name in 2006. [2] In 2011, Mandiant received funding from Kleiner Perkins Caufield & Byers and One Equity Partners to expand its staff and grow its business-to-business operations, providing incident response and general security consulting along with incident management products to major global organizations, governments, and Fortune 100 companies. [3] [ additional citation(s) needed ]
Mandiant is the creator of OpenIOC (Open Indicators of Compromise), an extensible XML schema for the description of technical characteristics that identify threats, security hackers' methodologies, and evidence of compromise. In 2012, its revenues were over $100 million, up 76% from 2011. [4]
In February 2013, Mandiant released a report documenting evidence of cyber attacks by the People's Liberation Army, [5] specifically Pudong-based PLA Unit 61398, [6] targeting at least 141 organizations in the United States and other English-speaking countries extending as far back as 2006. [7] In the report, Mandiant referred to the espionage unit as "APT1". [8]
In December 2013, Mandiant was acquired by FireEye for $1 billion. [9] [10] In October 2020, the company announced Mandiant Advantage, a subscription-based SaaS platform designed to augment and automate security response teams which combined the threat intelligence gathered by Mandiant and data from cyber incident response engagements; [11] in December, the company investigated a major supply chain attack by SolarWinds on U.S. government infrastructure. [12] [13] [14]
In May 2021, Mandiant was contracted to assist in the response to a ransomware incident impacting Colonial Pipeline, a fuel pipeline operator that supplies close to half of the gasoline, diesel, and other fuels to the East Coast of the U.S. [15] [16] In June, the company was spun off FireEye as part of the latter's acquisition by Symphony Technology Group. [17] [18] In August, the company acquired Intrigue, which specialized in surface management. [19]
In 2022, Axios reported that Mandiant reporters identified a pro-China disinformation campaign targeting American voters ahead of the 2022 midterm elections. [20]
In March 2022, it was announced that the company would be acquired by Google for $5.4 billion and subsequently integrated into the Google Cloud division. [21] Following the announcement, Fortune reported that while the deal could face antitrust scrutiny, the acquisition "could help increase competition" rather than harm it. [22]
In April 2022, it was reported that the Department of Justice (DOJ) Antitrust Division was probing the deal for potential violations of federal antitrust law. [23] However, Mandiant revealed in July 2022 that the DOJ granted the acquisition approval. [24] Following a review over potential competition concerns, the Australian Competition & Consumer Commission (ACCC) announced it would not oppose the deal. [25]
On September 12, 2022, the deal closed and integration between Mandiant and Google Cloud began. Following the acquisition, Mandiant was allowed to maintain its brand as a subsidiary of Google Cloud. [26] [27]
Adobe Inc., originally called Adobe Systems Incorporated, is an American multinational computer software company incorporated in Delaware and headquartered in San Jose, California. It has historically specialized in software for the creation and publication of a wide range of content, including graphics, photography, illustration, animation, multimedia/video, motion pictures, and print. Its flagship products include Adobe Photoshop image editing software; Adobe Illustrator vector-based illustration software; Adobe Acrobat Reader and the Portable Document Format (PDF); and a host of tools primarily for audio-visual content creation, editing and publishing. Adobe offered a bundled solution of its products named Adobe Creative Suite, which evolved into a subscription software as a service (SaaS) offering named Adobe Creative Cloud. The company also expanded into digital marketing software and in 2021 was considered one of the top global leaders in Customer Experience Management (CXM).
Aon PLC is an American multinational financial services firm that sells a range of risk-mitigation products, including Commercial Risk, Investment, Wealth, Health and Reinsurance solutions. The firm also provides data and analytics services, strategy consulting through Aon Inpoint and investment banking advisory through Aon Securities. Aon has approximately 50,000 employees in 120 countries.
Cisco Systems, Inc., commonly known as Cisco, is an American-based multinational digital communications technology conglomerate corporation headquartered in San Jose, California. Cisco develops, manufactures, and sells networking hardware, software, telecommunications equipment and other high-technology services and products. Cisco specializes in specific tech markets, such as the Internet of Things (IoT), domain security, videoconferencing, and energy management with leading products including Webex, OpenDNS, Jabber, Duo Security, and Jasper. Cisco is one of the largest technology companies in the world ranking 74 on the Fortune 100 with over $51 billion in revenue and nearly 80,000 employees.
Nuance Communications, Inc. is an American multinational computer software technology corporation, headquartered in Burlington, Massachusetts, that markets speech recognition and artificial intelligence software.
Broadcom Inc. is an American designer, developer, manufacturer, and global supplier of a wide range of semiconductor and infrastructure software products. Broadcom's product offerings serve the data center, networking, software, broadband, wireless, storage, and industrial markets. As of 2022, some 78 percent of Broadcom's revenue was coming from its semiconductor-based products and 22 percent from its infrastructure software products and services.
SolarWinds Corporation is an American company that develops software for businesses to help manage their networks, systems, and information technology infrastructure. It is headquartered in Austin, Texas, with sales and product development offices in a number of locations in the United States and several other countries. The company was publicly traded from May 2009 until the end of 2015, and again from October 2018. It has also acquired a number of other companies, some of which it still operates under their original names, including Pingdom, Papertrail and Loggly. It had about 300,000 customers as of December 2020, including nearly all Fortune 500 companies and numerous agencies of the US federal government.
Trellix is a privately held cybersecurity company founded in 2022. It has been involved in the detection and prevention of major cybersecurity attacks. It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks.
An advanced persistent threat (APT) is a stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period. In recent times, the term may also refer to non-state-sponsored groups conducting large-scale targeted intrusions for specific goals.
The United States has often accused the government of China of attempting to unlawfully acquire U.S. military technology and classified information as well as trade secrets of U.S. companies in order to support China's long-term military and commercial development. Chinese government agencies and affiliated personnel have been accused of using a number of methods to obtain U.S. technology, including espionage, exploitation of commercial entities, and a network of scientific, academic and business contacts. Prominent espionage cases include Larry Wu-Tai Chin, Katrina Leung, Gwo-Bao Min, Chi Mak and Peter Lee.
Cyberwarfare by China is the aggregate of all combative activities in the cyberspace which are taken by organs of the People's Republic of China, including affiliated advanced persistent threat groups, against other countries.
Dmitri Mikhailovich Alperovitch is an American think-tank founder, investor, philanthropist, podcast host and former computer security industry executive. He is the chairman of Silverado Policy Accelerator, a geopolitics think-tank in Washington, D.C. and a co-founder and former chief technology officer of CrowdStrike. Alperovitch is a naturalized U.S. citizen born in Russia who came to the United States in 1994 with his family.
PLA Unit 61398 is the Military Unit Cover Designator (MUCD) of a People's Liberation Army advanced persistent threat unit that has been alleged to be a source of Chinese computer hacking attacks. The unit is stationed in Pudong, Shanghai.
Symphony Technology Group (STG) is an American private equity firm based in Menlo Park, California. Its Chairman and CEO is Dr. Romesh Wadhwani, who founded the firm in 2002.
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides cloud workload and endpoint security, threat intelligence, and cyberattack response services. The company has been involved in investigations of several high-profile cyberattacks, including the 2014 Sony Pictures hack, the 2015–16 cyber attacks on the Democratic National Committee (DNC), and the 2016 email leak involving the DNC.
Makan Delrahim is an Iranian-American attorney and lobbyist. From 2017 to 2021, Delrahim served under President Donald Trump as Assistant Attorney General for the Department of Justice Antitrust Division.
Charming Kitten is an Iranian government cyberwarfare group, described by several companies and government officials as an advanced persistent threat.
Double Dragon is a hacking organization with alleged ties to the Chinese Ministry of State Security (MSS). Classified as an advanced persistent threat, the organization was named by the United States Department of Justice in September 2020 in relation to charges brought against five Chinese and two Malaysian nationals for allegedly compromising more than 100 companies around the world.
In 2020, a major cyberattack suspected to have been committed by a group backed by the Russian government penetrated thousands of organizations globally including multiple parts of the United States federal government, leading to a series of data breaches. The cyberattack and data breach were reported to be among the worst cyber-espionage incidents ever suffered by the U.S., due to the sensitivity and high profile of the targets and the long duration in which the hackers had access. Within days of its discovery, at least 200 organizations around the world had been reported to be affected by the attack, and some of these may also have suffered data breaches. Affected organizations worldwide included NATO, the U.K. government, the European Parliament, Microsoft and others.
Ghostwriter also known as UNC1151 is a hacker group allegedly originating from Belarus. According to the cybersecurity firm Mandiant, the group has spread disinformation critical of NATO since at least 2016.