Sources: the US DOJ discovered the SolarWinds breach in late May 2020, months before its public disclosure in December 2020, but was unaware of its significance
In May 2020, the US Department of Justice stumbled upon Russian hackers in its network, but did not realize the significance of what it had found for six months. Tweets: @lilyhnewman Tweets: Lily Hay Newman / @lilyhnewman : DOJ actually detected the SolarWinds hack in its network back in May 2020 and Microsoft, Mandiant, SW all looked at it at the time, but didn't grasp what they were seeing. Six months later Mandiant publicly exposed the campaign. @KimZetter back in @WIRED! https://www.wired.com/...
Context & Ripple Effects
When Mandiant publicly exposed the SolarWinds campaign in December 2020, the victim list already included Treasury — whose senior-leadership email system Sen. Ron Wyden said was breached beginning in July — and DHS internal communications. This new reporting adds DOJ to that list far earlier than publicly understood: Russian hackers were in its network in May 2020.
The striking detail is who else looked: per Lily Hay Newman's account, Treasury's admission came only after public exposure, while DOJ, Microsoft, Mandiant, and SolarWinds all examined the DOJ activity in May 2020 and none grasped what they were seeing. That six-month gap now frames later inquiries into how SolarWinds itself was compromised, including through its engineering offices in Czechia, Poland, and Belarus, and the FOIA-released window of potential access to treasury.gov addresses.
First-order effects
- DOJ operated for roughly half a year with Russian hackers inside its network before understanding what its own telemetry showed, retroactively extending the campaign's footprint among cabinet-level agencies beyond Treasury and DHS.
- Microsoft, Mandiant, and SolarWinds are now documented as having reviewed the May 2020 DOJ activity without identifying a supply-chain intrusion — shifting the accountability question from 'who lacked visibility' to 'who failed to interpret the evidence they had.'
Second-order effects
- Investigators' lines of inquiry into SolarWinds' own compromise — including its Czechia, Poland, and Belarus offices — carry more weight, since a miss this deep at DOJ suggests the tradecraft defeated expert human review, not just automated alerts.
- The FOIA lawsuit documents showing potential access to all treasury.gov addresses from July 6 to October 12, 2020 reinforce a pattern in which victims learned the true scope of the campaign years afterward, sustaining pressure on agencies for complete timelines.
Third-order effects
- When DOJ, Microsoft, and Mandiant each held pieces of the same evidence and none connected them, federal incident-response practice faces a structural question about relying on single-vendor or single-agency first-pass triage for state-grade intrusions.
- If sophisticated campaigns can dwell unnoticed despite multiple expert examinations, government procurement logic trends toward continuous verification and assume-breach postures across the software supply chain — though how quickly doctrine changes remains an open question.
The trend: State-backed supply-chain espionage is outpacing defenders' ability to interpret their own security data, stretching time-to-understanding far beyond time-to-detection.