Supply chain β›“ Supply Chain

Japanese Prime Minister's Cabinet Office Third-Party Breach (April 2021)

πŸ“… 2021-04-01 🏒 Soliton (FileZen application)
Primary Source β†—

Incident Details

Hacking campaign targets FileZen file-sharing network appliances. Threat actors are using two vulnerabilities in a popular file-sharing server to breach corporate and government systems and steal sensitive data as part of a global hacking campaign that has already hit a major target in the Japanese Prime Minister's Cabinet Office. The attacks target FileZen , a popular file-sharing network appliance from Japanese firm Soliton, and are eerily similar to the attacks that targeted Accellion’s FTA file-sharing systems in late 2020, early 2021. Both appliances work in the same manner. They are used to store large files that can’t be sent via email. Users typically upload files on a FileZen server and then use a web-based panel to obtain links that they can share with fellow employees or persons outside of their organization. Third-party company: Soliton (FileZen application).

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Soliton (FileZen application)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-04-01 Breach occurred
  2. 2023-01-26 Publicly disclosed