Investigation finds Pentagon, NASA, FBI, State Dept., other agencies used HP, SAP, Symantec, McAfee software that underwent code reviews by Russian government
WASHINGTON/MOSCOW (Reuters) - Major global technology providers SAP (SAPG.DE), Symantec (SYMC.O) and McAfee have allowed Russian authorities …
Context & Ripple Effects
This investigation widens a scrutiny arc that had been narrowing on one vendor. Through 2017, the focus was Kaspersky Lab: the House committee demanded seven years of Kaspersky-related documents from 22 agencies, and weeks before this story, [[a:925222|Safran was reported to have sold the FBI fingerprint-analysis software containing undisclosed code from a Kremlin-linked firm]] without telling its customer.
What changed with this report is scope: the exposure runs through mainstream Western enterprise vendors — HP, SAP, Symantec, McAfee — whose products passed through mandatory Russian government code reviews as a condition of doing business in Russia, and which sit on Pentagon, NASA, FBI and State Department networks. The question shifts from 'which Russian company did we buy?' to 'whose hands touched the code in everything we bought?'
First-order effects
- The named agencies now face pressure to inventory where SAP, Symantec, McAfee and HP products that underwent Russian state review run on their networks — the same remediation problem that surfaced when [[a:944648|Kaspersky software was found still present on federal systems nearly two years after its ban]].
- SAP, Symantec and McAfee must defend or restructure their Russian certification programs, since the reviews that won them Russian market access are now a liability in their larger US government business.
Second-order effects
- Western vendors with mandatory foreign code-review regimes face a forced choice between government-market revenue in Moscow and Washington, pushing them toward segmented builds or exit from the Russian certification track.
- Federal buyers can no longer treat a Western brand as proof of supply-chain integrity, so procurement due diligence extends from vendor identity to build and review pipelines — raising compliance costs across every contractor selling into these agencies.
Third-order effects
- If the pattern holds, US software procurement institutionalizes provenance auditing — knowing who reviewed or compiled the code, not just who sells it — a shift the [[a:961288|SolarWinds analysis showing compromised code inside Cisco, Intel, Nvidia and VMware environments]] would soon make unavoidable.
- The Kaspersky-to-SolarWinds sequence points toward structural decoupling: governments treating any foreign-mandated code inspection as a potential intelligence surface, fragmenting global software markets along security-bloc lines.
The trend: Government software procurement is moving from blacklisting individual Russian vendors to auditing the code-review and build pipelines of every supplier, making supply-chain provenance a standing national-security criterion.