The encyclopedia · Software & IT · Operational decision · 2020
Hackers hid in SolarWinds' update — 18,000 organizations installed the backdoor
A state-sponsored hack compromised SolarWinds' Orion update pipeline in 2020. 18,000 organizations, including the US Treasury and DOJ, installed the backdoor.
SolarWinds · 2020-12
What happened
In December 2020, cybersecurity firm FireEye discovered that hackers had compromised SolarWinds' Orion network management software by inserting a backdoor into a legitimate software update. The compromised update was distributed to approximately 18,000 organizations, including US government agencies (Treasury, Justice, Commerce, Homeland Security) and Fortune 500 companies.
The attack was a 'supply chain' compromise: rather than hacking individual targets, the attackers infiltrated the software vendor's build process and let the victims install the malware themselves through a routine update. The backdoor, called SUNBURST, was active for approximately nine months before detection.
The US government attributed the attack to Russia's SVR (foreign intelligence service). SolarWinds' stock fell over 40%, and the company faced lawsuits and congressional scrutiny. The case illustrated the vulnerability of software supply chains: when a trusted vendor's update mechanism is compromised, every customer becomes a target, and the attack is invisible because it arrives through the most trusted channel — a signed software update.
Why it happened
- Hackers compromised SolarWinds' build pipeline and inserted a backdoor into a legitimate software update.
- 18,000 organizations installed the compromised update, including US government agencies.
- The backdoor was active for ~9 months before detection by FireEye.
- The attack exploited the trust inherent in signed software updates — the most trusted distribution channel.
The lesson
The most dangerous attack arrives through your most trusted channel. SolarWinds' customers installed the malware because it came as a signed update. Supply chain security is the foundation.
Aftermath
SolarWinds overhauled its build security and development practices. The US government issued executive orders on software supply chain security. The case prompted the industry to adopt software bills of materials (SBOMs) and zero-trust architectures.
Sources
- CISA — AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations (SolarWinds Orion supply chain)
- 2020 United States federal government data breach — Wikipedia
spotted an error? The club wants to know.
More like this
The MOVEit breach hit 2,500 organizations — because one file transfer tool had a zero-day
Okta's support engineer was screen-shared into — and 366 customers were breached
LastPass was hacked twice in 2022 — the second breach exposed password vaults
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.