Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

TeamCity was reported as a possible factor in the SolarWinds compromise, but the available record does not establish that attackers used it to get into SolarWinds. In February 2021, SolarWinds’ CEO told the Senate the company had no evidence TeamCity was the entry point; he said the possibility was neither ruled out nor proven.

What the reports said about TeamCity

In January 2021, reports said U.S. intelligence agencies and private security specialists were investigating whether JetBrains’ TeamCity software had played a role in the SolarWinds attack. The report described an investigative question, not a confirmed breach through TeamCity. SecurityWeek noted that SolarWinds had not confirmed a definitive connection: SecurityWeek’s report.

TeamCity is JetBrains software for continuous integration and deployment: it helps automate building and delivering software. JetBrains said SolarWinds was a TeamCity customer. JetBrains CEO Maxim Shafirov said the company had not been contacted by a government or security agency and was not aware of an investigation. He added that, if TeamCity had been used, misconfiguration could have been involved, while stressing that JetBrains had no details beyond public information. These were JetBrains’ statements, not independent findings: JetBrains’ statement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What SolarWinds told the Senate

At a February 18, 2021 Senate Select Committee on Intelligence hearing, Senator Marco Rubio asked SolarWinds CEO Sudhakar Ramakrishna whether TeamCity could have been the attackers’ initial entry point. Ramakrishna said investigators had narrowed their hypotheses but still had several to examine. His answer was that SolarWinds had “no evidence that it was the backdoor used to get into SolarWinds,” while also saying the possibility had not been eliminated or proven. The hearing transcript records that distinction.

So the answer to “Did SolarWinds confirm TeamCity was how attackers got in?” is no. The company’s public testimony left the possibility open at that point, but supplied no evidence establishing it.

What the investigation established about the Orion build

SolarWinds’ investigation update described attackers compromising credentials and gaining access to the Orion development environment. It said the attackers used SUNSPOT to manipulate the automated build process and inject the SUNBURST backdoor into Orion software. This explains why build systems were relevant to investigators: compromising a build process can put malicious code into software updates distributed to customers. It does not identify TeamCity as the compromised application or prove that it was the route into SolarWinds. See SolarWinds’ investigation update.

Customer and victim figures are not TeamCity counts

Two figures mentioned at the hearing describe different scopes, and neither is a count of TeamCity-related victims:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Senator Rubio described up to 18,000 SolarWinds Orion customers as having received the backdoored software. That does not mean all those customers suffered a confirmed follow-on compromise.
  • FireEye CEO Kevin Mandia referred to more than 17,000 companies as compromised by the implant. His figure was not a TeamCity victim count.

The cited record does not establish a TeamCity-specific victim total.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the 2023 TeamCity vulnerability is a separate case

A December 2023 joint government advisory described Russian SVR-affiliated actors exploiting TeamCity vulnerability CVE-2023-42793. The advisory said agencies had not observed that access being used in a manner similar to the 2020 SolarWinds compromise. The later activity involved a specific vulnerability and is not evidence that TeamCity caused the earlier SolarWinds attack: the joint advisory.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.