Back to the archive

The encyclopedia · Software & IT · Operational decision · 2020

Hackers hid in SolarWinds' update — 18,000 organizations installed the backdoor

A state-sponsored hack compromised SolarWinds' Orion update pipeline in 2020. 18,000 organizations, including the US Treasury and DOJ, installed the backdoor.

SolarWinds · 2020-12

What happened

In December 2020, cybersecurity firm FireEye discovered that hackers had compromised SolarWinds' Orion network management software by inserting a backdoor into a legitimate software update. The compromised update was distributed to approximately 18,000 organizations, including US government agencies (Treasury, Justice, Commerce, Homeland Security) and Fortune 500 companies.

The attack was a 'supply chain' compromise: rather than hacking individual targets, the attackers infiltrated the software vendor's build process and let the victims install the malware themselves through a routine update. The backdoor, called SUNBURST, was active for approximately nine months before detection.

The US government attributed the attack to Russia's SVR (foreign intelligence service). SolarWinds' stock fell over 40%, and the company faced lawsuits and congressional scrutiny. The case illustrated the vulnerability of software supply chains: when a trusted vendor's update mechanism is compromised, every customer becomes a target, and the attack is invisible because it arrives through the most trusted channel — a signed software update.

Why it happened

  • Hackers compromised SolarWinds' build pipeline and inserted a backdoor into a legitimate software update.
  • 18,000 organizations installed the compromised update, including US government agencies.
  • The backdoor was active for ~9 months before detection by FireEye.
  • The attack exploited the trust inherent in signed software updates — the most trusted distribution channel.
What it cost18,000 organizations compromised; stock fell 40%+catastrophic

The lesson

The most dangerous attack arrives through your most trusted channel. SolarWinds' customers installed the malware because it came as a signed update. Supply chain security is the foundation.

Aftermath

SolarWinds overhauled its build security and development practices. The US government issued executive orders on software supply chain security. The case prompted the industry to adopt software bills of materials (SBOMs) and zero-trust architectures.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →