Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SolarWinds hack was a software supply-chain attack: intruders tampered with the process used to build Orion network-management software, so malicious code reached customers inside legitimate updates. The incident showed how a breach at one trusted supplier can open doors across many organizations—while leaving attackers free to pursue only a smaller number of high-value targets.

How did SUNBURST get into Orion updates?

Attackers entered SolarWinds’ build environment and inserted the SUNBURST backdoor into Orion builds. CISA said the affected Orion versions were released between March and June 2020. Because the updates appeared to come through SolarWinds’ normal distribution channel, customers could receive the malicious code through a software path they ordinarily trusted.

This is the defining risk of a software supply-chain compromise: an attacker targets the process or supplier that many organizations depend on, rather than breaking into every customer separately. The trusted delivery route can provide broad initial access, but it does not mean every recipient is selected for the same follow-on activity.

What was the timeline?

Date What is established
September 2019 SolarWinds’ SEC filing said its investigation identified suspicious activity in the company’s systems as early as this month.
March–June 2020 CISA said affected Orion versions were released during this period.
December 2020 SolarWinds publicly disclosed the incident after FireEye notified the company of the attack.
April 2021 CISA, NSA and FBI formally attributed the activity and the supply-chain compromise to Russian Foreign Intelligence Service (SVR) actors.
October 30, 2023 The SEC announced fraud and internal-control charges against SolarWinds and CISO Timothy Brown. The announcement described allegations, not a final court finding.

How many organizations were actually compromised?

SolarWinds reported up to 18,000 downloads of affected updates. That is an exposure figure, not a count of hacked companies or confirmed victims. A customer that did not install an affected update—or installed it on a server without internet access—could not be affected through SUNBURST’s command-and-control path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The campaign reached government agencies, critical-infrastructure entities and private-sector organizations. The available figures do not establish one definitive total of confirmed victim organizations. The important distinction is that a compromised supplier can create an opportunity across a large customer base, even if the attacker’s subsequent activity focuses on a much smaller set of targets.

Who was behind the attack, and what were the names?

In April 2021, CISA, the National Security Agency and the FBI attributed the activity to Russian Foreign Intelligence Service actors. Microsoft commonly used the name Nobelium for the activity; U.S. government advisories use the SVR attribution.

SUNBURST is also known as Solorigate. SolarWinds describes it as malicious code inserted into Orion builds. Do not treat every SolarWinds-related malware name or indicator as interchangeable: CISA’s analysis identifies SUPERNOVA as separate malware associated with a separate actor and event.

What should an organization do after a trusted update is compromised?

CISA’s remediation guidance is written for federal agencies, while also encouraging critical-infrastructure, state and local, and private-sector organizations to apply it as appropriate. Its response priorities include:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Isolate affected Orion systems. Contain potentially affected systems so they cannot continue communicating or provide a route into other parts of the environment.
  2. Rebuild from trusted sources. Do not assume that removing a suspicious file restores confidence in a potentially compromised system. Re-establish affected systems using sources and processes the organization can trust.
  3. Investigate identity systems and cloud accounts. Review Active Directory and Microsoft 365 for signs of follow-on activity, not just evidence on the Orion server.
  4. Assess credentials and access. Determine whether credentials may have been exposed during later stages of the intrusion and reset them where warranted.

These steps reflect the possibility that a supplier compromise may be followed by activity elsewhere in a customer’s environment. Organizations should use CISA’s guidance for the applicable systems and context rather than treating this list as a substitute for an incident-specific investigation.

What security lessons does SUNBURST leave?

The incident makes a case for layered defenses around software production, privileged access and the systems that manage an organization’s network. The controls below follow the documented attack path and CISA’s remediation priorities; they are risk-reduction measures, not proof that any single control would have prevented SUNBURST.

  • Protect build and release integrity. Restrict and monitor access to build environments, verify release processes, and protect code-signing keys and other privileged credentials.
  • Know what software is deployed. Maintain a software inventory and use software bills of materials (SBOMs) where they improve visibility into components and dependencies.
  • Constrain management systems. Limit the network access and privileges of systems that administer infrastructure, and monitor their outbound connections for unexpected behavior.
  • Keep independent evidence. Preserve logs outside the systems they describe so an intruder who gains administrative access cannot easily erase every useful record.
  • Practice supplier-compromise response. Rehearse how to isolate affected software, validate trusted rebuilds, investigate identity systems and coordinate decisions when a vendor update itself is in question.

When assessing a supplier or comparing security approaches, examine build and release integrity, signing-key protection, software inventory and SBOM visibility, privileged-access controls, network segmentation and egress monitoring, independent logging, and the ability to investigate and rebuild. Those dimensions connect supplier assurance to the work an organization must be able to do if trust in an update fails.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did the SEC say about SolarWinds’ disclosures?

On October 30, 2023, the SEC announced fraud and internal-control charges against SolarWinds and CISO Timothy Brown. The SEC alleged that the company overstated its cybersecurity practices and understated known risks before and during the SUNBURST disclosure period. Those statements describe the allegations at the time of the announcement, not a final judicial finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SEC Enforcement Director Gurbir S. Grewal said the action “underscores our message to issuers: implement strong controls calibrated to your risk environments and level with investors about known concerns.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.