- Today
- Holidays
- Birthdays
- Reminders
- Cities
- Atlanta
- Austin
- Baltimore
- Berwyn
- Beverly Hills
- Birmingham
- Boston
- Brooklyn
- Buffalo
- Charlotte
- Chicago
- Cincinnati
- Cleveland
- Columbus
- Dallas
- Denver
- Detroit
- Fort Worth
- Houston
- Indianapolis
- Knoxville
- Las Vegas
- Los Angeles
- Louisville
- Madison
- Memphis
- Miami
- Milwaukee
- Minneapolis
- Nashville
- New Orleans
- New York
- Omaha
- Orlando
- Philadelphia
- Phoenix
- Pittsburgh
- Portland
- Raleigh
- Richmond
- Rutherford
- Sacramento
- Salt Lake City
- San Antonio
- San Diego
- San Francisco
- San Jose
- Seattle
- Tampa
- Tucson
- Washington
Chinese Hackers Exploit Ivanti VPN Flaws to Breach Dozens of Customers
Cybersecurity report reveals how private equity-driven cuts compromised critical Ivanti security products.
Published on Feb. 23, 2026
Got story updates? Submit your updates here. ›
According to a new report by Bloomberg, Chinese hackers breached the network of Ivanti subsidiary Pulse Secure in 2021, exploiting a secret backdoor in the company's VPN software to gain access to 119 other organizations that used the same VPN product. The breach highlights how cost-cutting measures and layoffs at Ivanti following its acquisition by private equity firm Clearlake Capital Group in 2017 compromised the security of the company's critical technologies.
Why it matters
The Ivanti breach is the latest example of how private equity-driven consolidation and cost-cutting in the tech industry can undermine cybersecurity, as institutional knowledge and security expertise are lost. It also raises broader concerns about the security of remote access tools and VPNs, which have become critical infrastructure for many organizations during the pandemic.
The details
According to the report, the Chinese hackers exploited a backdoor they had planted in Pulse Secure's VPN software to gain access to Ivanti's network in 2021. From there, they were able to breach 119 other unnamed organizations that were using the same VPN product. Cybersecurity firm Mandiant also reportedly alerted Ivanti that the hackers had breached European and U.S. military contractors using the vulnerable VPN.
- In February 2021, Ivanti discovered the breach of its Pulse Secure subsidiary.
- In early 2024, the U.S. cybersecurity agency CISA ordered federal agencies to disconnect their Ivanti VPN appliances within two days due to active exploitation of vulnerabilities.
The players
Ivanti
A software giant that acquired Pulse Secure, a provider of VPN appliances, in 2017.
Clearlake Capital Group
The private equity firm that acquired Ivanti in 2017, leading to rounds of cost-cutting and layoffs that compromised the security of Ivanti's products.
Mandiant
The cybersecurity firm that alerted Ivanti that hackers had exploited the VPN vulnerability to breach European and U.S. military contractors.
What’s next
Ivanti and Mandiant did not respond to requests for comment, and it is unclear what steps the companies or affected organizations have taken to address the breach and secure their systems.
The takeaway
The Ivanti breach highlights the broader cybersecurity risks posed by private equity-driven consolidation and cost-cutting in the tech industry, as critical security expertise and institutional knowledge can be lost. It underscores the importance of maintaining robust security practices and oversight, even as companies seek to streamline operations.
Boston top stories
Boston events
Mar. 10, 2026
Boston Bruins vs. Los Angeles KingsMar. 10, 2026
Lights: COME GET YOUR GIRL TOUR 2026Mar. 10, 2026
We Had a World



