News: 1625639520

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Mega-distie SYNNEX attacked and Microsoft cloud accounts it tends tampered

(2021/07/07)


Updated Technology distributor SYNNEX has admitted that its systems and Microsoft accounts it tends have been attacked, after the National Committee of the US Republican Party (RNC) named it as the source of a recent security incident.

Bloomberg on Tuesday [1]reported that APT 29, aka Cozy Bear, last week attacked the RNC which, as the organising entity of the US Republican Party, holds all sorts of interesting and sensitive data. Cozy Bear was also [2]named as the entity behind the supply chain attack on SolarWinds

In response to the Bloomberg report, the RNC quickly named mega-distributor SYNNEX as the source of the breach, said no data was accessed, and that it has worked with Microsoft to get the situation is under control.

[3]https://t.co/ITOq7ggK5m [4]pic.twitter.com/5ufz6p1kHm — Danielle Alvarez (@Danielle_Alva) [5]July 6, 2021

SYNNEX ’fessed up to its involvement, in a [6]statement that admits “it is aware of a few instances where outside actors have attempted to gain access, through SYNNEX, to customer applications within the Microsoft cloud environment.”

[7]Here's what Russia's SVR spy agency does when it breaks into your network, says US CISA infosec agency

[8]It was Russia wot did it: SolarWinds hack was done by Kremlin's APT29 crew, say UK and US

[9]FYI Russia is totally hacking the West's labs in search of COVID-19 vaccine files, say UK, US, Canada cyber-spies

The nature of the RNC’s activities and hint of Cozy Bear’s involvement mean this incident is potentially another online skirmish between the USA and Russia. US President Biden recently told his Russian counterpart Vladimir Putin to stop his compatriots using digital weaponry — a call that Putin rebuffed by saying that his nation is the real victim. Biden said he “made it clear that we will not tolerate attempts to violate our democratic sovereignty or destabilize our democratic elections, and we would respond”. It remains to be seen if this incident is deemed worthy of response.

SYNNEX distances itself from Kaseya

SYNNEX’s statement is also notable for stating: “These actions could potentially be in connection with the recent cybersecurity attacks of Managed Service Providers, or MSPs” — almost certainly a reference to recent troubles at [10]Kaseya and SolarWinds.

The statement adds: “While SYNNEX provides many services as part of its overall IT distribution business, including supporting Microsoft cloud applications, it is not an MSP in the context mentioned in recent media.”

[11]

And indeed, it is not. But like all distributors, SYNNEX has in recent years tried to grow beyond the box-moving and licence-slinging business, and, in its word, “stems design and integration services for the technology industry to a wide range of enterprises.”

[12]

[13]

Those offerings can include overseeing cloud accounts for customers — either by managing licences or with more substantial hands-on consultancy.

That Tech Data merger SYNNEX Corp stockholders last week [14]approved the previously announced merger of the distie with Tech Data. The transaction is expected to close in the second half this year, subject to the usual regulatory approvals. If it goes through, the combined company will have approximately $57bn in estimated pro forma annual revenues and over 22,000 staffers.

Tech Data is currently wholly owned by funds managed by [15]Apollo Global .

For its fiscal Q2 ended May 31, 2021, SYNNEX reported $5.857bn in revenues, up 31 per cent from $4.47bn in Q2 2020. For its full fiscal year 2020 ended 30 November, SYNNEX reported turnover of $24.68bn, up 3.9 per cent over 2019, adn GAAP net income of $529.2m, up from $500.7m.

And just like MSPs, or the likes of Kaseya and SolarWinds, SYNNEX and other distributors are therefore potentially a gateway to attack numerous other entities.

If Cozy Bear and other miscreants have started attacking disties, that is therefore very scary indeed. Doubly so to SYNNEX, which is currently working its way through a merger with rival distie Tech Data. Once that transaction concludes, the combined company will be the planet’s largest tech distributor and an even tastier target.

Note, too, that SYNNEX’s statement says it’s aware of “a few instances” of concern. The RNC may therefore not be the only client to feel the rancid breath of Cozy Bear wafting uncomfortably close. ®

Updated to add at 08:48 UTC on 07/07/2021:

Michael Urban, president of worldwide technology solutions distribution at SYNNEX, told The Reg in a statement: “This morning, we responded to media reports over the weekend that referred to SYNNEX in reference to the Kaseya attack. We do not have a relationship with Kaseya and do not use its systems. “We are conducting a thorough review of a few instances in which outside actors have attempted to gain access, through SYNNEX, to customer applications within the Microsoft cloud environment. These instances did not involve ransomware.

Get our [16]Tech Resources



[1] https://www.bloomberg.com/news/articles/2021-07-06/russian-state-hackers-breached-republican-national-committee

[2] https://www.theregister.com/2021/04/15/solarwinds_hack_russia_apt29_positive_technologies_sanctions/

[3] https://t.co/ITOq7ggK5m

[4] https://t.co/5ufz6p1kHm

[5] https://twitter.com/Danielle_Alva/status/1412529360033177601?ref_src=twsrc%5Etfw

[6] https://ir.synnex.com/news/press-release-details/2021/SYNNEX-Responds-to-Recent-Cybersecurity-Attacks-and-Media-Mentions/default.aspx

[7] https://www.theregister.com/2021/04/27/apt29_russia_svr_tactics_cisa/

[8] https://www.theregister.com/2021/04/15/solarwinds_hack_russia_apt29_positive_technologies_sanctions/

[9] https://www.theregister.com/2020/07/16/russia_coronavirus_hacking/

[10] https://www.theregister.com/2021/07/07/kaseya_saas_restart_fails/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YOV7QbmfBECPtPAwYjw6oQAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOV7QbmfBECPtPAwYjw6oQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOV7QbmfBECPtPAwYjw6oQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.prnewswire.com/news-releases/synnex-corporation-stockholders-approve-merger-with-tech-data-301323715.html

[15] https://www.theregister.com/2019/10/16/apollo_global_5bn_bid_to_buy_tech_data_report/

[16] https://whitepapers.theregister.com/



At first

Winkypop

Hackers thought they’d broken into a 4Chan forum, but no, it was the RNC after all.

Mega-distie SYNNEX

tip pc

never heard of them.

also why ALL the bold text at the bottom of the article under the heading "SYNNEX distances itself from Kaseya"?

I was expecting the statement from "Mega-distie SYNNEX" but was just conjecture.

* Knghtktty is not going to ask how zucchini got into the discussion ...