UPDATED 21:04 EDT / FEBRUARY 22 2021

SECURITY

VC firm Sequoia Capital suffers data breach, investor information stolen

Sequoia Capital, one of the most famous venture capital firms in Silicon Valley has suffered a data breach with investor information likely stolen.

Officially referred to by the firm as a “cybersecurity incident,” it’s believed that the attack vector was via an employee being phished. Whether malware or ransomware was involved in the data breach is not clear with Sequoia informing its investors of the breach on Friday, Feb. 19.

The data potentially stolen is said to include personal and financial information. Axios reported Feb. 20 that Sequoia told investors that it has been monitoring the dark web, the shady corner of the internet where illicit goods and services change hands, and has not seen any indication that compromised information is being traded or otherwise exploited.

In a statement, Sequoia said that its security team responded promptly to investigate the data breach, that outsider cybersecurity experts had been hired to “help remediate the issue” and that law enforcement has been contacted. The specific use of language — to “help remediate the issue” — could suggest that the attack is ongoing and hence may involve ransomware as opposed to simply malware. A phishing attack that simply delivered malware should be in most circumstances fairly easy to fix.

“We regret that this incident has occurred and have notified affected individuals,” Sequoia added. “We have made considerable investments in security and will continue to do so as we work to address constantly evolving cyber threats.”

Founded in 1972, Sequoia Capital has been a prolific investor in tech startups and counts among its most successful investments Apple Inc., Atari Corp., Google LLC, Oracle Corp., Nvidia Corp., PayPal Holdings Inc., LinkedIn, Stripe Inc., YouTube, Instagram, Yahoo and WhatsApp, among many others. Sequoia was an early investor in those companies, delivering billions in profits in the process.

“Phishing attacks are a real threat for many organizations,” Joseph Carson, chief security scientist and advisory chief information security officer at privileged access management company Thycotic Software Ltd., told SiliconANGLE. “However, not all phishing security incidents are equal and successful phishing attacks that compromise employees with privileged access or access to privileged data can have a serious impact either from ransomware or data theft.”

Privileged access continues to be a major challenge for organizations, Carson added. “Privileged access is no longer just about domain admins and it is also important to consider business users who have access to sensitive data as privileged access,” he said.

Image: Sequoia Capital

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU