In March 2021, Qualys disclosed that attackers had accessed files stored on a third-party Accellion File Transfer Appliance (FTA) it used for some customer-support file transfers. Qualys said the incident was confined to that appliance: its investigation found no impact on Qualys Cloud Platform customer data, production environments, codebase, Agents, or Scanners. The company later said an independent forensic firm found no movement from the appliance into other Qualys environments.
What happened in the Qualys Accellion incident?
Qualys used Accellion FTA to transfer information for customer support, including temporary transfers of files customers manually uploaded. Qualys described the affected server as a standalone appliance in a segregated demilitarized zone (DMZ), separate from systems hosting Qualys products and from its production customer-data environment.
Qualys’s March 3, 2021 disclosure gives this sequence of events:
- Accellion released a hotfix for the relevant zero-day vulnerability on December 21, 2020.
- Qualys said it applied the hotfix on December 22.
- Qualys received an integrity alert on December 24 and immediately isolated the affected server.
- Qualys later shut down the affected FTA servers and provided customers with alternatives for support-related file transfers.
- Qualys publicly disclosed the incident on March 3, 2021.
Qualys’s incident update and its March 3 investor-relations disclosure describe the company’s account of the response.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
What data was accessed, and what did Qualys say was unaffected?
Qualys and Accellion investigated unauthorized access to files hosted on the FTA server. Qualys said the impact was limited to files stored on that appliance. It stated that Qualys Cloud Platform customer data, production environments, codebase, Agents, and Scanners were not affected, and that its platforms suffered no operational impact. Those are findings reported by Qualys about its investigation, not an independently verified inventory of every potentially exposed file.
In an April 2, 2021 update, Qualys said postings staged by the threat actor matched files the company had already identified and that its analysis had not revealed additional files. Qualys also said an independent forensic firm found no lateral movement from the FTA server into another Qualys environment. Ben Carr, Qualys’s chief information security officer, said the findings confirmed the impact was contained to files stored on the appliance at the time of the incident. Read Qualys’s April update.
Did the breach affect Qualys Cloud Platform customer data?
Qualys said it did not. Its disclosures distinguish files on the support-related FTA appliance from customer data hosted on the Qualys Cloud Platform and from the systems that operate Qualys products. The company’s investigation found no impact to those production systems or data. Qualys’s conclusion should be attributed to the company; the public disclosures do not provide an outside audit of every file or a full public inventory of file contents.
How many customers or files were affected?
Qualys’s reviewed public disclosures do not give a complete count of affected customers or files, or a complete public inventory of what the files contained. The company said it identified and notified customers it believed may have had files on the server, and gave those customers a list of their files to review.
Rank #3
Qualys also cautioned against treating every email address mentioned in threat-actor posts as evidence that the person’s files were on the appliance. It said it found email addresses without a corresponding file on the server and described posts that associated file names and addresses belonging to different customers.
How did the incident fit into the wider Accellion FTA campaign?
The incident occurred amid a broader campaign exploiting vulnerabilities in Accellion FTA, a legacy file-transfer product. A February 24, 2021 CISA and partner-agency advisory described exploitation affecting organizations internationally and across government and private-sector industries, and included technical details and defensive guidance.
Rank #4
Separately, Accellion’s February 22 statement relayed Mandiant’s reported identification of UNC2546 in attacks and data theft involving legacy FTA, as well as extortion threats involving publication of stolen data. That account concerns the broader campaign; it does not establish that UNC2546 was responsible for the Qualys incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should affected Qualys customers do?
Qualys said it contacted customers it believed may have had files on the appliance and recommended that those organizations review the files. Any follow-up should depend on what a customer’s files contained: Qualys suggested measures such as resetting passwords or changing keys when warranted by the files involved, not as a blanket instruction for every Qualys customer.
Quick Recap
Best Value
- If Qualys notified your organization, review the file list it provided and identify any credentials, keys, or other sensitive information in those files.
- Reset passwords or rotate keys if the exposed files contained those secrets or if your security team otherwise determines a change is warranted.
- Contact your Qualys technical account manager or Qualys Support with questions about the files or the incident.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

