[News](/news)

Malwarebytes hacked by SolarWinds hackers

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Malwarebytes hacked by SolarWinds hackers

##### [Edward Kost](/team/edward-kost)

January 19, 2021

Malwarebytes, a U.S. cyber-security firm, has announced that it was hacked by the same threat actors responsible for the [SolarWinds breach](https://www.upguard.com/news/u-s-treasury-emails-breached).

Malwarebytes is not a SolarWinds customer, so this breach is not related to the SolarWinds [supply chain attack](https://www.upguard.com/blog/supply-chain-attack).

In its [official statement of the incident](https://blog.malwarebytes.com/malwarebytes-news/2021/01/malwarebytes-targeted-by-nation-state-actor-implicated-in-solarwinds-breach-evidence-suggests-abuse-of-privileged-access-to-microsoft-office-365-and-azure-environments/), Malwarebytes confirmed that the hackers abused applications with privileged access to Microsoft Office 365 and Azure environments. The result was a breach involving a limited subset of Malwerbyte’s internal company emails.

“The investigation indicates the attackers leveraged a dormant email protection product within our Office 365 tenant that allowed access to a limited subset of internal company emails. We do not use Azure cloud services in our production environments.” Malwarebytes said in their statement.

This breach was achieved through an Azure Active Directory vulnerability allowing users to escalate privileges by assigning credentials to applications.

Malwarebytes discovered that the threat actors added a self-signed certificate to ultimately request access to internal emails through MSGraph.

“In our particular instance, the threat actor added a self-signed certificate with credentials to the service principal account. From there, they can authenticate using the key and make API calls to request emails via MSGraph.”

Securing Azure tenants is challenging, especially through vendors that could be specifically [targeted in a third-party breach campaign](https://www.upguard.com/product/vendorrisk).

The Cybersecurity and Infrastructure Security Agency (CISA) released an alert outlining the tactics used by the SolarWinds threat actors. Initial attack vectors often involve [Password Guessing](https://www.upguard.com/blog/brute-force-attack), Password Spraying and/or exploiting inappropriately secured administrative for service credentials.

CISA identified a transition from user context to administrator rights for privilege escalation. This means [privilege escalation prevention tactics](https://www.upguard.com/blog/privilege-escalation) could potentially fend off such attacks.

[Internal communications](https://www.upguard.com/news/mimecast-breach) seems to be the new coveted commodity amongst cybercriminals. This could be a purely coincidental development, or evidence of a broad reconnaissance campaign by the same threat actor.

## How secure is Malwarebytes?

Malwarebytes develops cybersecurity software that provides antivirus, anti-malware, and threat detection services for computers and mobile devices. The company offers products including browser protection, VPN services, identity theft monitoring, and scam detection tools for individual consumers and small businesses.

* View our free preliminary report on Malwarebytes’s security posture
* 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

[View Malwarebytes's score](/security-report/malwarebytes)

[View score](/security-report/malwarebytes)

[https://www.malwarebytes.com/](/security-report/malwarebytes)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

## Latest news

Stay up-to-date with the latest news in cybersecurity.

[](/news/hugging-face-data-breach-2026-07-20)

#### [Hugging Face data breach: key facts and what we know so far](/news/hugging-face-data-breach-2026-07-20)

A data breach involving Hugging Face was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 20, 2026

[](/news/ey-data-breach-2026-07-19)

#### [EY data breach: what happened and what's at risk](/news/ey-data-breach-2026-07-19)

A data breach involving EY was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

#### [South Florida Injury & Convenient Care data breach exposes names and Social Security numbers](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

A data breach involving South Florida Injury & Convenient Care was reported in July 2026. See incident details, impact on customers, and security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/park-west-psychology-data-breach-2026-07-16)

#### [Park West Psychology data breach: what happened and what's at risk](/news/park-west-psychology-data-breach-2026-07-16)

A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

#### [Fall River Municipal Credit Union data breach: what happened and what's at risk](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

A data breach involving Fall River Municipal Credit Union was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [](#)

July 14, 2026

[](/news/npcil-data-breach-2026-07-16)

#### [NPCIL data breach: World Leaks claims exposure of Kudankulam Nuclear Power Plant files](/news/npcil-data-breach-2026-07-16)

A data breach involving NPCIL was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 14, 2026

[View all news](/news)

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
