GAO Details Massive SolarWinds Cyberattack and Ongoing Government Response

The Government Accountability Office outlines how Russian intelligence executed the widespread SolarWinds breach and how federal agencies are responding. GAO is currently conducting a comprehensive review of the incident to release a public report later this year.

The SolarWinds cybersecurity breach stands as one of the most sophisticated hacking campaigns ever directed at the federal government and private sector. Beginning in September 2019, Russian Foreign Intelligence Service actors breach SolarWinds, a Texas-based network management software company, and initially inject test code into its Orion product suite. By February 2020, the threat actors successfully hide malicious code within Orion software updates, which SolarWinds then distributes to approximately 18,000 customers without realizing the updates are compromised.

This trojanized code creates a hidden backdoor that gives the threat actors remote access to the infected computer systems. Because federal agencies widely use SolarWinds to monitor network activity, the breach allows the attackers to easily penetrate government information systems. The threat actors specifically target a smaller subset of high-value customers, including key federal entities, with the primary goal of conducting espionage.

Cybersecurity firm FireEye detects the intrusion on its own systems in November 2020 and promptly notifies SolarWinds about the Orion platform compromise. Microsoft also reveals that the threat actors exploit the situation to compromise some of its cloud platforms, granting the hackers unauthorized network access. The Government Accountability Office is currently performing a comprehensive review of this far-reaching incident and plans to issue a public report later this year.

Read More at the original source →