{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing"},"incident":{"title":"Sequoia Capital investor data exposed after employee falls for phishing email","date":"2021-02","date_precision":"month","victim_org":"Sequoia Capital","sector":"Financial Services","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Business Email Compromise"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed; the associated fraudulent transfer attempt was reported as unsuccessful.","records_affected":null,"threat_actor":null,"summary":"Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.","how_it_worked":"An employee at the firm received and acted on a phishing email, handing over credentials that gave the attacker access to their corporate mailbox. The intruder used that mailbox to read stored correspondence containing investor personal and financial details, and attempted to leverage the account for fraudulent payment instructions in the style of a business email compromise, which was not successful. Sequoia notified affected limited partners, engaged outside investigators and law enforcement, and offered credit monitoring. No malware deployment or wider network intrusion was reported.","lessons":"Phishing-resistant MFA on cloud mailboxes plus alerting on anomalous mailbox rules and sign-in locations catches this pattern in hours rather than weeks.","confidence":"Reported","sources":[{"title":"Scoop: Sequoia Capital says it was hacked","url":"https://www.axios.com/2021/02/20/sequoia-capital-says-it-was-hacked","publisher":"Axios"},{"title":"VC Giant Sequoia Capital Informs Investors of Data Breach","url":"https://www.securityweek.com/vc-giant-sequoia-capital-informs-investors-data-breach/","publisher":"SecurityWeek"},{"title":"VC giant Sequoia Capital discloses data breach after failed BEC attack","url":"https://www.bleepingcomputer.com/news/security/vc-giant-sequoia-capital-discloses-data-breach-after-failed-bec-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing","year":2021,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2021-sequoia-capital-investor-data-exposed-after-employee-falls-for-phishing"}}