Kevin Mandia: Building Mandiant, Uncovering SolarWinds
When a company discovers it's been hacked, there's a short list of people it calls, and for two decades Kevin Mandia's name has sat near the top of it.
A former Air Force special agent, he founded Mandiant in 2004, co-wrote the standard text on incident response and, in February 2013, published the report that pinned years of corporate espionage on a specific unit of the Chinese army, down to a street in Shanghai.
Then, in December 2020, the breach hunter found a breach inside his own company. What he did with that discovery changed how the world understood supply chain attacks, and it was far from his last act.
Kevin Mandia at a Glance
- Mandia studied computer science at Lafayette College and forensic science at George Washington University, then served in the US Air Force as a computer security officer at the Pentagon and a special agent in the Office of Special Investigations.
- By 2000 he was director of computer forensics at Foundstone, George Kurtz's consultancy, and co-writing Incident Response & Computer Forensics, now in its third edition.
- He founded Mandiant in 2004 and in February 2013 released the APT1 report, tying hundreds of terabytes stolen from at least 141 organizations to PLA Unit 61398 in Shanghai.
- FireEye announced its acquisition of Mandiant on January 2, 2014, and Mandia became FireEye's chief executive in 2016.
- On December 8, 2020, FireEye disclosed that a nation-state had stolen its red-team tools. The investigation exposed the SolarWinds supply chain attack.
- FireEye sold its products business and name to private equity for $1.2 billion in 2021, and Google bought what remained, Mandiant, for $5.4 billion in 2022.
- Mandia stepped down as Mandiant's CEO in 2024, co-founded Ballistic Ventures and in March 2026 launched Armadin, an AI offensive-security startup, with $189.9 million.
- In October 2026 Armadin raised another $255.5 million at a valuation above $2.5 billion, a month after Amazon elected Mandia to its board.
The Life of Kevin Mandia
Mandia's Air Force Years
Kevin Mandia came to security through investigation rather than programming. He took a computer science degree at Lafayette College and a master's in forensic science at George Washington University, and then joined the US Air Force.
There he served as a computer security officer at the Pentagon and as a special agent in the Air Force Office of Special Investigations, the service's detective branch. The job was figuring out who'd broken into a system and how, at a time when almost nobody called that a career.
Mandia would spend the next thirty years making it one.
Writing the Playbook
By 2000 he was director of computer forensics at Foundstone, the consultancy George Kurtz had started the year before. Both men would go on to found companies that defined the industry, and in 2026 Kurtz would join the board of Mandia's.
Mandia also wrote the field's textbook. Incident Response & Computer Forensics, co-written with Chris Prosise and Matt Pepe, laid out how to investigate a breach step by step, and a third edition with Jason Luttgens and Matthew Pepe is still the standard reference.
Founding Mandiant
In 2004 Mandia founded Mandiant. Where most security companies sold products to keep attackers out, Mandiant sold the thing nobody wanted to need: investigators who showed up after the attackers were already in.
That vantage point gave the firm something unusual. Working one breach after another, it saw the same intruders, the same tools and the same working hours, over and over.
APT1
On February 18, 2013, Mandiant published a report on a group it called APT1. The firm had traced the group's activity to four large networks in Shanghai, two of which served the Pudong New Area, and concluded that APT1 was the People's Liberation Army's Unit 61398, headquartered partly on Datong Road in the Gaoqiao district.
The report said APT1 had "systematically stolen hundreds of terabytes of data from at least 141 organizations," and estimated the unit was staffed by hundreds, perhaps thousands, of people.
Private companies didn't accuse foreign armies by name in 2013. The New York Times reported it the day the report came out, and Reuters wrote days later that Mandiant had gone viral. The report made attribution a product, and it made Mandia famous.
FireEye
On January 2, 2014, FireEye announced it'd acquired Mandiant. Mandia became the combined company's chief operating officer, and in May 2016, after months of rumors, FireEye's board replaced David DeWalt with Mandia as chief executive.
He now ran a public company that sold both the products and the people, and he kept the investigators at the center of it.
Hacked
On December 8, 2020, FireEye disclosed that it'd been hacked by a nation-state, which had stolen the proprietary red-team tools the company used to find weaknesses in customers' networks. It was an embarrassing admission for a security vendor, made in public and in detail.
The investigation led somewhere bigger. FireEye found that updates to SolarWinds' Orion software had been poisoned with a backdoor, digitally signed with a SolarWinds certificate, from March through May 2020. Within a week Brian Krebs was reporting that the US Treasury and Commerce departments had been breached through the same supply chain.
The SolarWinds campaign became the defining espionage story of the decade, and it came to light because the victim was a company that investigates breaches for a living.
In June 2021 FireEye sold its products business and its name to Symphony Technology Group for $1.2 billion. What remained took the Mandiant name again, with Mandia as its CEO.
On March 8, 2022, Google announced it'd buy Mandiant for $5.4 billion, and the deal closed on September 12, 2022, bringing a team spread across 22 countries into Google Cloud. In May 2024 Mandia stepped down as Mandiant's chief executive.
Armadin and Amazon
Mandia had already co-founded Ballistic Ventures, where he funds and mentors security founders as a general partner. Then he started over.
Armadin surfaced quietly in late 2025 with a $24 million seed round and launched publicly in March 2026 with a $189.9 million Series A. Its product deploys swarms of specialized AI agents that probe a customer's attack surface, exploit what they find and chain the results into validated attack paths.
"AI lets an attacker find and chain weaknesses faster than any human team can respond," Mandia said when the company raised another $255.5 million on October 1, 2026, at a valuation above $2.5 billion, in a round co-led by Andreessen Horowitz and Accel.
A month earlier, on September 8, 2026, Amazon elected him to its board of directors. He also sits on the National Security Telecommunications Advisory Committee and CISA's Cybersecurity Advisory Committee.
Kevin Mandia: The Responder Who Went on Offense
Mandia's career is the story of incident response growing up: from an Air Force investigator's side job to a $5.4 billion acquisition.
Along the way he did two things nobody else had dared. He named a Chinese army unit in public, and he told the world his own company had been hacked, then followed the trail to SolarWinds.
Now he's building an AI swarm to find security holes before real attackers do. The man you call after the breach would rather you never had to.
QUOTE:
"Amateurs hack systems, professionals hack people."