An in-depth look inside the US DOJ and Volexity's investigation into the SolarWinds hack, one of the most sophisticated cyberespionage campaigns of the decade
I'd like to highlight this bit. Zero trust, my arse. Lots of new details in this report. https://www.wired.com/... Tweets: Stephane Taillat / @staillat : A great work by @KimZetter @WIRED on the SolarWinds hack (and on the investigation) with new materials : https://www.wired.com/... Kim Zetter / @kimzetter : This feature story is a companion piece to news story I wrote last week about how Justice Department/Mandiant/Microsoft actually uncovered the SolarWinds hack 6 months before it got publicly exposed, but didn't know the significance of what they'd found https://www.wired.com/... Kim Zetter / @kimzetter : The story has a considerable number of new details, including this one highlighted by @GossiTheDog that shows how the government failed to protect its servers from the attack https://twitter.com/... Kim Zetter / @kimzetter : We still don't have full account of what SW hackers took from gov systems. Why? Fed agencies were lax about logging network activity. They “couldn't tell...how far across the network [hackers] had gone,” source told me. It was also “really difficult to tell what they had taken” https://twitter.com/... Sherrod DeGrippo / @sherrod_im : Midnight Blizzard aka NOBELLIUM attack walkthrough. I'd like to see this done as an attack chain animation showing the spread and various timelines. Fantastic story. Nice work @KimZetter https://www.wired.com/... Eric Geller / @ericgeller : .@KimZetter's SolarWinds tick-tock is full of great details about one of the most consequential incident response operations in history. https://www.wired.com/... I want to highlight a few of the themes that remain very relevant today. https://twitter.com/... Lily Hay Newman / @lilyhnewman : There's been lots of SolarWinds hack coverage and great reporting but this from @KimZetter is THE SolarWinds story. It has new info and you'll finally feel like you understand the timeline/how everything worked after reading. Plus it's just a gripping saga https://www.wired.com/... Kim Zetter / @kimzetter : Eric gets exactly right the broad issues that are highlighted in my story. The SolarWinds campaign exposed a lot of failures in industry and government and underscored how much work both sides still have to do to address what the hacking campaign revealed https://twitter.com/...
Context & Ripple Effects
Kim Zetter's feature closes a loop that began in December 2020, when reports surfaced that state-sponsored hackers had penetrated US Treasury, Commerce, and DHS internal communications. By February 2021 the damage was still expanding — attackers who reached the federal court system likely saw sealed documents holding trade secrets and espionage targets. What this piece adds is the uncomfortable prequel: Justice Department, Mandiant, and Microsoft had actually found the intrusion six months before it became public, without grasping its significance.
The investigation by DOJ and Volexity also explains why the breach was so hard to scope: federal agencies lacked adequate logging, so defenders could not determine how far the attackers moved or what was taken. That failure directly feeds the policy fight already underway over whether the NSA should get new spying powers precisely because it is barred from monitoring domestic networks.
First-order effects
- The DOJ, Mandiant, and Microsoft now face hard questions about why an intrusion they detected six months early wasn't escalated, while Volexity's forensic work becomes the reference record for what the attackers touched.
- Federal agencies — Treasury among them, whose senior-leadership email Sen. Ron Wyden confirmed was breached from July onward — are exposed as unable to answer basic questions about their own compromise because of missing logs.
Second-order effects
- FireEye's move to release a free network-auditing tool for SolarWinds attacker techniques signals how private-sector responders, not agencies, became the ones distributing defensive capability during the crisis.
- The documented logging gaps strengthen the case from officials pushing new NSA domestic-monitoring authorities, forcing privacy advocates like Wyden into a counterargument about surveillance scope rather than the breach itself.
Third-order effects
- If the pattern holds, federal cybersecurity reform will center on mandatory telemetry and logging standards across civilian agencies — the precondition for any defender knowing the blast radius of a supply-chain compromise.
- The episode cements a structure where commercial incident-response firms effectively serve as the nation's forward detection layer, raising questions about accountability when they find something but no one connects it in time.
The trend: Cyberespionage response is consolidating around private-sector forensic firms and auditors because government networks lack both the monitoring legal authority and the logging to defend themselves.