2025 SentinelOne — China-linked reconnaissance/vendor-compromise activity targeting the firm (Ivanti CVE chain context)
Data compromised
Investigation-scoped vendor and corporate metadata—exact categories per SentinelOne communications summarized by outlets
Technical writeup
SentinelOne publicly described activity it attributed to China-linked adversaries who performed reconnaissance against SentinelOne infrastructure and compromised an IT services vendor used by the company; reporting framed the incident as an attempted intrusion pathway rather than a confirmed mass exfiltration from SentinelOne product clouds.
Root cause
Suspected nation-state campaign leveraging compromised vendor footprint and Ivanti-class vulns referenced in SentinelOne threat reporting (per trade press summarizing SentinelOne statements)
References
- https://www.cybersecuritydive.com/news/sentinel-one-china-hackers-it-vendor-critical-infrastructure/750116/
- https://thehackernews.com/2025/04/sentinelone-uncovers-chinese-espionage.html
- https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/