← SentinelOne

2025 SentinelOne — China-linked reconnaissance/vendor-compromise activity targeting the firm (Ivanti CVE chain context)

2025 Unknown records affected Share on X

Data compromised

Investigation-scoped vendor and corporate metadata—exact categories per SentinelOne communications summarized by outlets

Technical writeup

SentinelOne publicly described activity it attributed to China-linked adversaries who performed reconnaissance against SentinelOne infrastructure and compromised an IT services vendor used by the company; reporting framed the incident as an attempted intrusion pathway rather than a confirmed mass exfiltration from SentinelOne product clouds.

Root cause

Suspected nation-state campaign leveraging compromised vendor footprint and Ivanti-class vulns referenced in SentinelOne threat reporting (per trade press summarizing SentinelOne statements)

References