Security firm Stormshield discloses data breach, theft of source code

Security firm Stormshield discloses data breach, theft of source code

  • French cyber-security firm Stormshield, a major provider of security services and network security devices to the French government, said today that a threat actor gained access to one of its customer support portals and stole information on some of its clients.
  • The company is also reporting that attackers managed to steal parts of the source code for the Stormshield Network Security (SNS) firewall, a product certified to be used in sensitive French government networks, as part of the intrusion.
  • The Stormshield incident is currently being treated as a major security breach inside the French government. In its own press release, ANSSI officials said they’ve put Stormshield SNS and SNI products “under observation” for the duration of the investigation.
  • Stormshield, which is a fully-owned subsidiary of Airbus CyberSecurity, could not say if the attack was conducted by a nation-state group at this point in the investigation.

– Catalin Cimpanu | February 4, 2021