Sources: investigators are checking if SolarWinds was hacked via its offices in Czechia, Poland, and Belarus, where the company moved much of its engineering
Those behind the widespread intrusion into government and corporate networks exploited seams in U.S. defenses and gave away nothing to American monitoring of their systems.
New York Times
Context & Ripple Effects
The inquiry builds on the earlier finding that the Treasury breach involved a SolarWinds product flaw that the company characterized as a supply-chain attack. Investigators are now testing whether the company’s engineering footprint in Czechia, Poland, and Belarus was part of the compromise path, rather than treating the affected product as the only relevant surface.
Related coverage subsequently widened the search to JetBrains as another possible entry point and found that many victims had no SolarWinds connection, reinforcing that the SolarWinds investigation was becoming a broader hunt for multiple access paths.
First-order effects
- SolarWinds’ engineering operations in Czechia, Poland, and Belarus become a specific focus of the investigation, alongside the compromised product and its customer deployments.
- U.S. investigators must trace potential access through development operations across those offices, expanding the evidence and systems relevant to the incident.
Second-order effects
- The expanding inquiry puts other software-development vendors under greater scrutiny as possible access points, as shown by the later examination of JetBrains.
- Organizations initially assessing exposure through SolarWinds alone face a broader incident-response scope when victims may have been reached through other routes.
Third-order effects
- The case points toward supply-chain investigations that assess the full software-development environment—including distributed engineering operations—rather than stopping at the delivered product.
- If this pattern persists, software suppliers’ geographic development footprints will become more central to customer and government assessments of security exposure.
The trend: Major software compromises are shifting incident response from a single-vendor product check toward tracing interconnected development and distribution pathways.
Related: SolarWinds · SolarWinds supply-chain attack report · JetBrains examined as possible entry point · Czechia · Poland
Related Coverage
- SolarWinds hack is an example of private equity firms wrecking software companies and degrading their products' security to the detriment of national security BIG · Matt Stoller
- How Russia's ‘Info Warrior’ Hackers Let Kremlin Play Geopolitics on the Cheap Wall Street Journal
- 9 big tech questions for 2021 Protocol · David Pierce
- Quick Hits — *** President Donald Trump affirmed a proposed 1% pay raise for civilian federal employees for 2021. Federal Computer Week
- SolarWinds hack may be much worse than originally feared The Verge · Kim Lyons
- Concern mounts over government cyber agency's struggle to respond to hack fallout CNN
- Start Up No.1455: SolarWinds hack worse than thought, hedge fund prods Intel, is the Turing Test dead?, Xiaomi's charger chat bites it, and more The Overspill · Charlesarthur
- Russian Hack Used Servers Inside US, Cybersecurity Company Says PYMNTS.com
- SolarWinds hack may have been much wider than first thought Engadget · Jon Fingas
- Is the US Government's Cybersecurity Agency Up to the Job? Slashdot · EditorDavid
- Cybersecurity firm FireEye says massive Russia hack was waged inside U.S. Axios
- Russian Hackers' Motive Baffles U.S.: Mere Espionage, or Worse? Bloomberg · William Turton
Discussion
-
@binarybits
Timothy B. Lee
on x
This is a good piece on how sociopathic private equity types laid the groundwork for the Solarwinds hack. https://mattstoller.substack.com/ ...
-
@nickconfessore
Nick Confessore
on x
An amazing detail about the penny-pinching SolarWinds CEO in this absolutely terrifying @nicoleperlroth @SangerNYT @julianbarnes story on our cyber-9/11. https://www.nytimes.com/... https://twitter.com/...
-
@hatr
Hakan
on x
A different (and, to me, interesting) way of looking at the Solarwinds-hack. https://mattstoller.substack.com/ ... https://twitter.com/...
-
@dangillmor
Dan Gillmor
on x
SolarWinds should be out of business for pure negligence, and its cheapskate chief executive should be sued by former customers for every dime he has. This crappy company compromised all of us with its wretched practices. https://www.nytimes.com/... Fine NYT reporting...
-
@brianmfloyd
Brian Floyd
on x
Yeah this is real bad https://www.nytimes.com/...
-
@timbray
Tim Bray
on x
Really strong edition of @matthewstoller's newsletter. It's not news that the PE sector is highly damaging to the economy, but the linkage to the SolarWinds story is particularly spine-chilling: https://mattstoller.substack.com/ ...
-
@wsj
@wsj
on x
Russia's relations with the West continue to sour, and the Kremlin sees the cyber operations as a cheap and effective way to achieve its geopolitical goals, analysts say https://www.wsj.com/...
-
@matthewstoller
Matt Stoller
on x
In Downfall of the West, episode #242 Orlando Bravo, the private equity billionaire responsible for the massive hack of Microsoft, the FBI, our nuclear weapons facilities, etc. was just named “Dealmaker of the Year” by Pitchbook. https://mattstoller.substack.com/ ...
-
@matthewstoller
Matt Stoller
on x
I wrote up how the massive hack of nuclear weapons facilities (and everyone else) is a result of billionaire private equity barons looting software firms and degrading the security of software products used by IT departments everywhere. https://mattstoller.substack.com/ ...
-
@elissabeth
Elissa Shevinsky
on x
Useful read on the perverse incentives that make cyber security - and national security - so difficult to maintain. https://twitter.com/...
-
@privacyde
Kirsten
on x
“Cybersecurity risk is akin to pollution,” a cost that neither gov nor business itself doesn't fully bear, but that the rest of society does. We should be aware. https://twitter.com/...
-
@denbrots
@denbrots
on x
As Understanding of Russian Hacking Grows, So Does Alarm “This is looking much, much worse than I first feared,” said Sen Mark Warner, D of VA &ranking member of the Senate Intel Com. “The size of it keeps expanding. It's clear the U.S. gov't missed it.” https://www.nytimes.com/.…
-
@sparksjls
Jason Sparks
on x
The more we learn about this intrusion campaign, the worse it gets. https://www.nytimes.com/... https://twitter.com/...
-
@bloombergme
Mike Bloomberg
on x
In which @matthewstoller makes clear what was inevitable; our national defense system is put at risk by P.E. gutted cyber security firms run by accountants... not cyber security professionals. https://mattstoller.substack.com/ ... https://twitter.com/...
-
@robert_spalding
General Spalding
on x
“Using passwords ripped form the movie Spaceballs is one thing, but it appears that lax security practice at the company was common, systemic, and longstanding...SolarWinds CEO, Kevin Thompson, ignored the risk.” https://mattstoller.substack.com/ ...
-
@ericgeller
Eric Geller
on x
The New York Times must be stopped. https://www.nytimes.com/... https://twitter.com/...
-
@georgikantchev
Georgi Kantchev
on x
For Russia, cyber operations are a relatively inexpensive and effective way to conduct geopolitics, said @BilyanaLilly https://www.wsj.com/...
-
@jamesschamus
James Schamus
on x
So, the catastrophic hack of US infrastructure and government is, of course, a story about private equity: How to Get Rich Sabotaging Nuclear Weapons Facilities by @matthewstoller https://mattstoller.substack.com/ ...
-
@pgroth
Paul Groth
on x
Software and data supply chains are more important than ever to understand and verify #provenance https://twitter.com/...
-
@grantstern
Grant Stern
on x
Russia isn't just breaking into **250 federal government networks** for no reason. This is INCREDIBLY DANGEROUS and Donald Trump isn't saying a word about it but installed cronies atop our NatSec institutions that are ignoring everything. https://www.nytimes.com/...
-
@anniejacobsen
Annie Jacobsen
on x
Huge👇 “Those questions have taken on particular urgency given that the breach was not detected by any of the government agencies that share responsibility for cyberdefense — [DoD, NSA, DHS] — but by a private cybersecurity company, FireEye.” https://www.nytimes.com/...
-
@file411
@file411
on x
DUCK ME “breach is far broader than first believed...Russia sent its probes only into a few dozen of the 18,000 government and private networks..it now appears Russia exploited multiple layers of the supply chain to gain access to as many as 250 networks” https://www.nytimes.com/…
-
@shashj
Shashank Joshi
on x
Burn it all down. “Some security experts said that ridding so many sprawling federal agencies of the S.V.R. may be futile and that the only way forward may be to shut systems down and start anew” https://www.nytimes.com/...
-
@ericgeller
Eric Geller
on x
Trump plans to issue three cyber-related “presidential determinations” soon, one of which transfers some authority from DoD to CISA, per new CNN story. Also in here: Trump appointees have been asking how SolarWinds intrusions could hurt him politically. https://www.cnn.com/... ht…
-
@zcohencnn
Zachary Cohen
on x
New: As US officials grapple w/ fallout from hack of government & private sector systems, questions are swirling about whether the agency tasked with protecting the nation from cyberattacks is up to the job. First story of 2021 w/ @vmsalama & @b_fung https://www.cnn.com/...
-
@marquardtglobal
Michael Marquardt
on x
Very well-sourced and professional reporting by @SangerNYT, @nicoleperlroth, and @julianbarnes. Difficult to come up with the right metaphor or analogy, but fair to say that Russian spies have secretly been roaming through government offices since March. https://www.nytimes.com/.…
-
@bwjones
Bryan William Jones
on x
My point over the last year, that centralized control and monitoring of IT infrastructure is a fundamentally flawed security philosophy has been given a substantial bit of weight by this hack. https://twitter.com/...
-
@biannagolodryga
Bianna Golodryga
on x
This just shouldn't happen: “Some of the compromised SolarWinds software was engineered in Eastern Europe, and American investigators are now examining whether the incursion originated there, where Russian intelligence operatives are deeply rooted.” https://www.nytimes.com/...
-
@rad_atl
Richard DeMillo
on x
1/ When I pointed out supply chain weaknesses in the voting machine industry in 2019 I didn't have the software supply chain specifically in mind, but, yes, we had better start treating these technologies with the seriousness they deserve: https://twitter.com/... https://twitter.…
-
@apolyakova
Dr Alina Polyakova
on x
Time and time again, Moscow is able to take advantage when the US focus is elsewhere. The hack affected 250+ federal agencies and businesses was “aimed not at the election system but at the rest of the US government and many large American corporations.” https://www.nytimes.com/.…
-
@anneapplebaum
Anne Applebaum
on x
An American president who empathize with America's enemies presided over the biggest Russian hack in history https://www.nytimes.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
None of the SolarWinds customers contacted by The New York Times in recent weeks were aware they were reliant on software that was maintained in Eastern Europe. Many said they did not even know they were using SolarWinds software until the breach.
-
@nicoleperlroth
Nicole Perlroth
on x
New deep dive with @SangerNYT on the SolarWinds hack found its 5-6X broader than initially believed with ~250 victims (MSFT tallied 40 initially). -The backdoored Orion software was built/maintained in Eastern Europe. -Concern another major vector used. https://www.nytimes.com/..…
-
@nytimes
@nytimes
on x
“This is looking much, much worse than I first feared.” As U.S. officials learn more about Russia's cyberattack, the scale of the damage continues to grow. https://www.nytimes.com/...
-
@biannagolodryga
Bianna Golodryga
on x
October 2019!!! It is becoming increasingly clear that missing this hack is one of the Trump Administration's largest & most consequential failures. 2nd only to COVID mismanagement. “The SolarWinds hacking, which began as early as October 2019,” https://www.nytimes.com/...
-
@mollymckew
Molly McKew
on x
“SolarWinds moved much of its engineering to satellite offices in the Czech Republic, Poland, and Belarus, were engineers had broad access to the Orion network management software that Russia's agents compromised.” Seriously, I can't. https://www.nytimes.com/...
-
@stengel
Richard Stengel
on x
“American officials responsible for cybersecurity are now consumed by what they missed for 9 months: a hacking, now believed to have affected upward of 250 federal agencies, that Russia aimed not at the election but at the rest of the US government.” https://www.nytimes.com/...