Sequoia Capital discloses data breach after failed BEC attack Data Breach


The US venture capital firm Sequoia Capital has published a notice of data breach after a hacker was able to gain access to the inbox of one of its employees as part of an unsuccessful business email compromise (BEC) attack that took place back in January.
Sequoia Capital has been around since 1972 and over the years it has invested in a number of high-profile tech companies including Apple, Nvidia, Google, Oracle, Cisco and more as well as numerous startups such as Airbnb, Dropbox, FireEye, Stripe, Square and WhatsApp.
Back in December of last year, the FBI sent out a Private Industry Notification (PIN) warning US businesses that cybercriminals has begun to abuse auto-forwarding rules in web-based email clients to increase the chances of success of their BEC attacks.
It seems Sequoia Capital should have heeded this warning as this exact technique was used by an attacker to gain access to its data and almost to its network.
Failed BEC attack
In a notice of data breach sent to those affected by the failed BEC attack, Sequoia Capital explained the steps it took once it learned that an unauthorized third party had gained access to one of its employee’s email accounts, saying:
“On or about January 20, 2021, we learned that an unauthorized third party had gained remote access to the business email mailbox of one Sequoia employee, with the apparent aim of conducting a wire diversion scam. Our investigation has found no evidence of compromise beyond this single mailbox. We quickly took steps to secure our network and began to investigate the incident with the support of outside cybersecurity experts.”
Thankfully the attacker was only able to breach one employee’s inbox and they did not gain access to any other resources or assets on Sequoia Capital’s network. However, the company did say that the personal information of fewer than 1,000 Californian residents may have been exposed in the attack.
The security experts hired by Sequoia Capital also found no evidence that this personal data was being sold or traded by cybercriminals on the dark web. To protect those whose information may have been exposed, the company is offering 24 months of free credit monitoring and identity theft protection from Experian.
Via BleepingComputer
The US venture capital firm Sequoia Capital has published a notice of data breach after a hacker was able to gain access to the inbox of one of its employees as part of an unsuccessful business email compromise (BEC) attack that took place back in January. Sequoia Capital has been…
Recent Posts
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
- DOGE can keep accessing government data for now, judge rules
- Humane’s AI Pin: all the news about the dead AI-powered wearable
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010