Network-monitoring software has the run of a network. It talks to the servers, the switches and the firewalls, and it reports back on all of them. SolarWinds Orion is that kind of product, and it was in use across large businesses and government agencies. Software like that is also patched on a schedule, by administrators who have no reason to treat one signed update differently from the last.
Between March and June of 2020, one of those updates carried a hidden backdoor. It was digitally signed by the vendor, and the businesses and agencies running Orion installed it the way anyone installs a trusted update. That update was the break-in.
The question worth answering is not how the signature was defeated, because it was not. The attacker did not tamper with the software after it shipped. It got into SolarWinds’ own build environment, the system that compiles Orion into the product customers download, and planted a small implant that researchers later named SUNSPOT. SUNSPOT’s job was to watch the build. Researchers described it as software that monitors running processes for those involved in compilation of the Orion product, which is to say it waited for the moment Orion was being compiled. When a build ran, it swapped in a modified source file that added the SUNBURST backdoor, so the backdoor was compiled straight into the product as an ordinary part of the build. It was engineered carefully, with safeguards so the build would not fail or throw errors that might tip off SolarWinds’ own developers that anything had changed.
The narration reaches for a bakery to make this concrete: someone gets into the kitchen of a trusted bakery and works something into the dough while the bread is being made, so every loaf comes out already tainted, then sealed and stamped with the bakery’s own label. The seal was never broken; it was applied to something already tampered with. That is what a supply-chain compromise is. Instead of attacking the target directly, the attacker goes after something the target already trusts, and lets that trust carry it in.
Then comes the number that gets misread. Roughly eighteen thousand organizations downloaded the poisoned update, and the figure invites you to picture eighteen thousand break-ins. That is not what happened. For almost all of those eighteen thousand the backdoor arrived and stayed dormant, never used. The download happened automatically; the intrusion that could follow it was deliberate and selective, and for the great majority it never came. Picture eighteen thousand buildings with the same faulty lock fitted on the front door. The lock is a genuine weakness in every one of them, but a weakness is not an intruder. Someone still has to choose your building, walk up, and come through. In the government’s own words, a much smaller number have been compromised by follow-on activity on their systems, and that follow-on activity is the part that was hand-selected.
The heaviest concentration of that selection was in the U.S. federal government. Government auditors later reported, citing an official from the National Security Council, that nine federal agencies were compromised. An earlier joint statement from the government, in January of 2021, had put it as fewer than ten. Those are the same finding at two moments, an interim count and where it settled.
Two of the nine show what the hands-on stage actually reached. The Department of the Treasury is listed in its own later budget documents among nine agencies significantly impacted, and it reported that all SolarWinds Orion products continued to remain offline across the Treasury enterprise environment while it cleaned up. Treasury requested about one hundred and fourteen million dollars to address the impact of the incident. That figure needs care: it was money requested to clean up and recover, not a loss and not a fine. At the Department of Homeland Security, according to a later report from its own inspector general, the incident resulted in senior DHS officials’ email accounts being compromised, and once inside the attacker granted itself the permissions it needed to reach other programs and applications while staying undetected.
That is the shape of the second stage. After the backdoor called home, the attacker stole credentials and forged the digital tokens that vouch for who is logged in. With those forged tokens it could slip into email and cloud accounts as though it were a legitimate user, moving through systems that had every reason to treat it as one of their own. Beyond government, U.S. officials said about one hundred private-sector companies were also compromised in the follow-on activity. That figure comes from the government’s own briefings rather than a document anyone can pull apart line by line, so it is best held as their stated estimate.
The story became public through a company caught in it first. In November of 2020, the cybersecurity firm FireEye, whose incident-response arm is known as Mandiant, discovered it had been breached itself. This is a firm that companies and government agencies hire to find the holes in their own defenses, and it had just found intruders inside its own network. On the eighth of December, 2020, it disclosed what had happened. What the attacker took was a specific set of tools, FireEye’s Red Team assessment tools. A Red Team is the offensive side of a security firm, the people paid to attack their own clients on purpose, with permission, so the weaknesses turn up before a real attacker finds them. The tools they use are, in effect, a working kit for breaking into well-defended networks. FireEye said the attacker had targeted and accessed the Red Team assessment tools it uses to test its customers’ security, and that it primarily sought information related to certain government customers.
There was a limit to what FireEye found taken. It said it had seen no evidence that the attacker exfiltrated data from its primary systems that store customer information. That was FireEye’s own assessment of its own systems, not a verdict that its customers were safe. Then it did something that turned the theft into a defence. Rather than keep quiet about the stolen kit, it publicly released more than three hundred countermeasures, ready-made ways for anyone to detect those tools in use, so the stolen kit was worth far less to whoever now held it. And when FireEye traced how the intruders had gotten in, the trail led back to a piece of software it ran in-house, its own SolarWinds Orion install.
Once SolarWinds and the U.S. government went public, they moved quickly. On the thirteenth of December, 2020, the U.S. Cybersecurity and Infrastructure Security Agency issued an emergency directive ordering federal agencies to immediately disconnect or power down SolarWinds Orion products. The next day, SolarWinds filed its own public disclosure. A few days later, on the seventeenth of December, CISA published a technical alert that gave the backdoor a name: SUNBURST.
The victim list reached one of the largest technology companies in the world. Microsoft confirmed that the attacker had accessed some of its internal source-code repositories. Source code is the human-readable blueprint of a piece of software, the instructions an engineer writes before it is turned into a running product. Microsoft said the attacker viewed source code in a small subset of its components across Azure, its cloud platform, along with Intune and Exchange, and that for a small number of repositories there was additional access, including in some cases downloading component source code. Viewing source code is not the same as changing the product, and Microsoft was specific about the limits. It said there was no access to the vast majority of source code. For nearly all of the repositories that were reached, only a few individual files were viewed. There was no case where all the repositories for any single product or service were accessed. Microsoft found no evidence of access to its production services or customer data, and it said the attacker was not able to gain access to privileged credentials, nor to use those forged-token techniques against Microsoft’s own corporate domains. The source code was viewed, not stolen, and not altered. The narration’s image for it is someone reading a few pages of a company’s recipe book over an employee’s shoulder: they may walk away knowing a little about how something is made, but they never touched the factory floor, and they never changed a single product coming off the line.
Attribution arrived in two stages. On the fifth of January, 2021, a joint statement from the U.S. government said the work was that of an advanced persistent threat actor, likely Russian in origin. On the fifteenth of April, 2021, the government made it formal, stating that it attributes this activity to the Russian Foreign Intelligence Service, the SVR. Anyone who followed the coverage will have heard the same actor called APT29, or Cozy Bear. Those are the names security researchers and vendors use for it, not a different or weaker guess, but the research community’s labels for the very same group the government named.
One more name from that period needs separating out, because it causes a common mix-up. SUPERNOVA. According to researchers at Unit 42, SUPERNOVA was a separate and unrelated piece of malware, placed by a different actor through a different Orion flaw. It was not part of this campaign, and it was not the SVR. It rode in on the same product’s name, and that is the whole of its connection to this story.
The final chapter is recent, and it played out in a courtroom rather than a network. In October of 2023, almost three years after the breach, the U.S. Securities and Exchange Commission brought civil charges against SolarWinds the company and against its chief information security officer, the executive responsible for the company’s security. It was the first time the regulator had gone after a company’s security executive personally over how a breach was disclosed. Everything the SEC said about what the company and that executive had done wrong was an allegation, the regulator’s claim in a lawsuit, not a proven fact. The SEC alleged, in short, that SolarWinds and its security chief had overstated the company’s security practices to investors and played down known risks. The company and the executive contested the charges. In July of 2024, a federal court dismissed most of the SEC’s claims. On the twentieth of November, 2025, the SEC voluntarily dismissed all of its remaining claims against both the company and the executive, with prejudice, which means they cannot be brought again. There was no financial penalty, no admission of wrongdoing, and no finding of liability. A court never ruled that SolarWinds or its security chief had broken the law, and the regulator abandoned the case entirely.
What is left is not a verdict on any one person, but an open question. A regulator tried to hold an individual security executive personally accountable for how a systemic breach was disclosed, and the case collapsed before it ever reached that judgment. Whether, and how, an individual should answer for a compromise that reaches through a trusted vendor into the federal government, is a question this case raised and did not settle.
Every organization that installed that Orion update had done nothing careless. It trusted a vendor it had every reason to trust, and that trust is exactly what carried the attacker in. There is no personal fix at the end of this one, because you cannot audit a vendor’s build server from your desk. What the record shows is the response the defenders reached for at the time: the emergency order to disconnect Orion, and the countermeasures FireEye released so its stolen tools could be spotted in use.
**Sources & further reading:**
- FireEye, disclosure of the compromise of its Red Team assessment tools (December 8, 2020), and the countermeasures it released publicly
- CISA, Emergency Directive 21-01, Mitigate SolarWinds Orion Code Compromise (December 13, 2020)
- SolarWinds Corporation, public disclosure filed December 14, 2020
- CISA, technical alert naming the SUNBURST backdoor (December 17, 2020)
- CrowdStrike, technical analysis of the SUNSPOT build-system implant (January 11, 2021)
- Joint statement of the FBI, CISA, ODNI and NSA (January 5, 2021)
- U.S. Government attribution of the activity to the Russian Foreign Intelligence Service, the SVR (April 15, 2021)
- U.S. Government Accountability Office, SolarWinds Cyberattack: Federal Response, Oversight, and Remaining Challenges (GAO-22-104746, 2022)
- U.S. Department of the Treasury, FY2022 Congressional Budget Justification
- U.S. Department of Homeland Security, Office of Inspector General, report on the department’s response to the SolarWinds incident
- Microsoft Security Response Center, Microsoft Internal Solorigate Investigation, Final Update (February 18, 2021)
- Unit 42 (Palo Alto Networks), SUPERNOVA analysis (December 17, 2020)
- U.S. Securities and Exchange Commission v. SolarWinds Corp. (S.D.N.Y.), complaint filed October 30, 2023; opinion of July 18, 2024; voluntary dismissal with prejudice of November 20, 2025
