← TD SYNNEX

2021 TD SYNNEX (Synnex) — cloud-reseller intrusion wave; Microsoft-tenant access attempts (SVR/Nobelium reporting)

2021 Unknown records affected Share on X

Data compromised

No standardized consumer leak count; political-party and enterprise tenant risk discussed in coverage

Technical writeup

During the July 2021 incident window around Kaseya-related ransomware chaos, Fremont-based IT distributor Synnex (now TD SYNNEX after later merger naming) disclosed that adversaries attempted to abuse its Microsoft cloud distribution relationships to reach end-customer Azure/365-style applications, characterizing successful pivots as limited to “a few instances” in CRN-paraphrased company statements. Bloomberg-sourced reporting ascribed motivation to Russian SVR (APT29/Nobelium) espionage aligned with the SolarWinds-era threat cluster; RNC said partner investigation found no data accessed in its tenant. Row summarizes supply-chain espionage risk without a public cumulative victim census.

Root cause

Nation-state espionage campaign leveraging IT distributor trust paths into customer cloud tenants (attribution and mechanics per press; no single CVE summary from vendor)

References