HomeSecuritySentinelOne: New details regarding the attempted breach

SentinelOne: New details about the attempted breach

SentinelOne has published more details about an attempted supply chain breach by Chinese hackers, via an IT and logistics services company that manages logistics infrastructure for the cybersecurity firm.

See also: Hackers exploit old AT&T data breach

SentinelOne breach

SentinelOne is an American provider of endpoint protection (EDR/XDR) solutions that protects critical infrastructure in the country, as well as many large enterprises. It is a high-value target for government agencies, as its breach could act as a springboard to access customer corporate networks and gain information about detection capabilities, facilitating the development of detection evasion techniques.

SentinelOne first reported the attempted breach in April, while the new report published describes the attack as part of a broader campaign, which targeted over 70 organizations worldwide , from June 2024 to March 2025.

Targets include organizations in the government, telecommunications, media, finance, industry, research, and IT sectors.

See also: Lee Enterprises says 40,000 people affected by breach

The campaign is divided into two groups of activity. The first, called PurpleHaze, is attributed to APT15 and UNC5174 and covers the period from September to October 2024.

SentinelOne: New details about the attempted breach

SentinelOne was targeted by both groups, once for reconnaissance purposes and once for a supply chain. The company suspects that the cybercriminals in both cases exploited vulnerabilities in exposed network devices, including Ivanti Cloud Service Appliances and Check Point gateways.

The PurpleHaze attempted to compromise SentinelOne in October 2024, with the attackers performing scans on the company's servers that were exposed to the internet via port 443, with the aim of capturing accessible services.

The attackers registered domain names that impersonated SentinelOne infrastructure, such as sentinelxdr[.]us and secmailbox[.]us. The most recent wave of activity is attributed to ShadowPad, which was conducted by APT41 between June 2024 and March 2025.

See also: Hacker arrested for breaching 5,000 hosting accounts

A key element highlighted by the above information is the increasing sophistication and persistence of state-sponsored cyber espionage, such as APT15 and APT41. Both groups use sophisticated techniques, such as registering deceptive domains and exploiting known vulnerabilities in network devices (such as Ivanti and Check Point), to gain access to critical infrastructure and infiltrate high-value environments.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS