Inside the SolarWinds Hack: How Russia Infiltrated U.S. Government
A sophisticated supply chain attack gave Russian intelligence agencies nine months of unfettered access to America's most sensitive networks
Published June 6, 2025

Case Details
Quick Facts
Classification:
Quick facts
In March 2020, attackers began injecting remote access malware into SolarWinds Orion software updates—a trusted tool relied upon by thousands of organizations worldwide, including multiple U.S. federal agencies. For nine months, the intrusion went undetected.
On December 8, 2020, cybersecurity firm FireEye discovered its own systems had been breached. While investigating the theft of their own red team tools, FireEye uncovered something far larger: evidence of a sophisticated supply chain attack targeting SolarWinds. Five days later, on December 13, FireEye and SolarWinds publicly disclosed the malware to the world.
The scope was staggering. Approximately 18,000 government and private computer networks had downloaded the trojaned software updates. Among the victims were five major U.S. departments—Justice, State, Treasury, Energy, and Commerce—along with the National Nuclear Security Administration, at least three state governments, and the city of Austin, Texas. Microsoft's business networks were also compromised, though the company confirmed no national security systems were affected.
Timeline
Infiltration begins
Russian SVR hackers begin by compromising the SolarWinds Orion software and inserting malicious code into updates.
Malware spreads
Through manipulated software updates, around 18,000 organizations worldwide are infected with the malicious software, including key US government agencies.
FireEye discovery
Cybersecurity company FireEye discovers that it has itself fallen victim to a highly sophisticated hacking attack.
Public disclosure
FireEye and US authorities make the massive cyberattack public. Investigations begin.
Scope becomes known
Further details about the depth and breadth of the infiltration become known. At least five key US government departments were affected.
Russia officially blamed
The US and the UK officially confirm that the Russian foreign intelligence service SVR is behind the SolarWinds hack.
Sanctions announced
The US government announces sanctions against Russian intelligence officers and institutions in response to the attack.
For between 12 and 14 days after installation, the malware remained dormant. Only then did it contact its command-and-control servers, giving attackers a window to carefully establish persistent access before defenders could detect suspicious network activity. Once activated, the intruders obtained nine months of unfettered access to top-level communications, court documents, and sensitive intelligence related to nuclear weapons.
"This is likely the worst intelligence disaster in U.S. history," one security analyst would later observe. The full damage extent remains unknown, and investigators warned that assessing the complete breach could take years.
U.S. officials moved quickly to attribute the attack. The Department of Homeland Security, FBI, and intelligence agencies, along with Secretary of State Mike Pompeo and Attorney General Bill Barr, all pointed to Russia's Foreign Intelligence Service (SVR), specifically the hacking group known as APT29, also called Cozy Bear or UNC2452. The attribution was based on technical evidence and a pattern of tactics matching prior Russian cyber operations, including the NotPetya attack on Ukraine in 2017.
Microsoft President Brad Smith added critical context: the supply chain method itself bore Russian fingerprints. Russia had pioneered this tactic years earlier when targeting Ukrainian infrastructure. The sophistication and patience required to compromise a software update pipeline, wait months before activating the malware, and carefully siphon intelligence suggested a state-sponsored operation with significant resources.
Key figures in uncovering the breach included FireEye CEO Kevin Mandia, who led his company's investigation and confirmed SolarWinds as the entry point, and Brad Smith, who helped researchers understand the broader implications of the attack. Multiple security firms—including Mandiant, Microsoft, DomainTools, ReversingLabs, Volexity, and Google's Threat Analysis Group—collaborated to analyze the malware and track its footprint.
Russia denied involvement. Despite the attribution by U.S. officials and the technical evidence linking the operation to Russian intelligence services, Moscow dismissed the allegations.
As of the available sources, no public prosecutions or verdicts had been announced. The SolarWinds hack remained an ongoing investigation into what many security experts regard as one of the most consequential cyberattacks against the United States government.
Sources
https://www.cbsnews.com/news/solarwinds-hack-russia-cyberattack-60-minutes-2021-07-04/
https://www.hypr.com/security-encyclopedia/solarwinds-breach
https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach
https://www.tandfonline.com/doi/full/10.1080/00396338.2021.1906001
Ask about this case
Answers from KrimiNyt's coverage onlyFollow this case
Get an email when a new documentary, podcast or book about Inside the SolarWinds Hack: How Russia Infiltrated U.S. Government appears, or when a verdict is reached.


