Case File

Inside the SolarWinds Hack: How Russia Infiltrated U.S. Government

A sophisticated supply chain attack gave Russian intelligence agencies nine months of unfettered access to America's most sensitive networks

🇺🇸 American

Published June 6, 2025

A computer screen displays the SolarWinds logo with malicious code running, symbolizing the cyberespionage breach orchestrated by the Russian SVR hackers.
EVIDENCE

Case Details

Quick Facts

Case Status
Solved
Location
Milpitas, California, USA

Quick facts

LocationMilpitas, California, USA

In March 2020, attackers began injecting remote access malware into SolarWinds Orion software updates—a trusted tool relied upon by thousands of organizations worldwide, including multiple U.S. federal agencies. For nine months, the intrusion went undetected.

On December 8, 2020, cybersecurity firm FireEye discovered its own systems had been breached. While investigating the theft of their own red team tools, FireEye uncovered something far larger: evidence of a sophisticated supply chain attack targeting SolarWinds. Five days later, on December 13, FireEye and SolarWinds publicly disclosed the malware to the world.

The scope was staggering. Approximately 18,000 government and private computer networks had downloaded the trojaned software updates. Among the victims were five major U.S. departments—Justice, State, Treasury, Energy, and Commerce—along with the National Nuclear Security Administration, at least three state governments, and the city of Austin, Texas. Microsoft's business networks were also compromised, though the company confirmed no national security systems were affected.

Timeline

1 March 2020

Infiltration begins

Russian SVR hackers begin by compromising the SolarWinds Orion software and inserting malicious code into updates.

1 March 2020

Malware spreads

Through manipulated software updates, around 18,000 organizations worldwide are infected with the malicious software, including key US government agencies.

8 December 2020

FireEye discovery

Cybersecurity company FireEye discovers that it has itself fallen victim to a highly sophisticated hacking attack.

13 December 2020

Public disclosure

FireEye and US authorities make the massive cyberattack public. Investigations begin.

1 February 2021

Scope becomes known

Further details about the depth and breadth of the infiltration become known. At least five key US government departments were affected.

15 April 2021

Russia officially blamed

The US and the UK officially confirm that the Russian foreign intelligence service SVR is behind the SolarWinds hack.

15 April 2021

Sanctions announced

The US government announces sanctions against Russian intelligence officers and institutions in response to the attack.

For between 12 and 14 days after installation, the malware remained dormant. Only then did it contact its command-and-control servers, giving attackers a window to carefully establish persistent access before defenders could detect suspicious network activity. Once activated, the intruders obtained nine months of unfettered access to top-level communications, court documents, and sensitive intelligence related to nuclear weapons.

"This is likely the worst intelligence disaster in U.S. history," one security analyst would later observe. The full damage extent remains unknown, and investigators warned that assessing the complete breach could take years.

U.S. officials moved quickly to attribute the attack. The Department of Homeland Security, FBI, and intelligence agencies, along with Secretary of State Mike Pompeo and Attorney General Bill Barr, all pointed to Russia's Foreign Intelligence Service (SVR), specifically the hacking group known as APT29, also called Cozy Bear or UNC2452. The attribution was based on technical evidence and a pattern of tactics matching prior Russian cyber operations, including the NotPetya attack on Ukraine in 2017.

Microsoft President Brad Smith added critical context: the supply chain method itself bore Russian fingerprints. Russia had pioneered this tactic years earlier when targeting Ukrainian infrastructure. The sophistication and patience required to compromise a software update pipeline, wait months before activating the malware, and carefully siphon intelligence suggested a state-sponsored operation with significant resources.

Key figures in uncovering the breach included FireEye CEO Kevin Mandia, who led his company's investigation and confirmed SolarWinds as the entry point, and Brad Smith, who helped researchers understand the broader implications of the attack. Multiple security firms—including Mandiant, Microsoft, DomainTools, ReversingLabs, Volexity, and Google's Threat Analysis Group—collaborated to analyze the malware and track its footprint.

Russia denied involvement. Despite the attribution by U.S. officials and the technical evidence linking the operation to Russian intelligence services, Moscow dismissed the allegations.

As of the available sources, no public prosecutions or verdicts had been announced. The SolarWinds hack remained an ongoing investigation into what many security experts regard as one of the most consequential cyberattacks against the United States government.

Sources

https://www.cbsnews.com/news/solarwinds-hack-russia-cyberattack-60-minutes-2021-07-04/

https://www.hypr.com/security-encyclopedia/solarwinds-breach

https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach

https://www.tandfonline.com/doi/full/10.1080/00396338.2021.1906001

Ask about this case

Answers from KrimiNyt's coverage only

Follow this case

Get an email when a new documentary, podcast or book about Inside the SolarWinds Hack: How Russia Infiltrated U.S. Government appears, or when a verdict is reached.

Share this post: