/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: state-sponsored hackers accessed US DHS internal communications as part of the campaign that penetrated US Treasury and Commerce departments

now five — hacked in major Russian cyberespionage campaign David Uberti / Wall Street Journal : Hack of Federal Agencies Shows Cyber Dangers to Supply Chains Tweets: Dustin Volz / @dnvolz : Can confirm DHS has also been hacked in the SolarWinds attack. DHS is not currently acknowledging their breach publicly. With Commerce and Treasury, that's three confirmed agency intrusions. I'm also told national security agencies and defense contractors have been compromised. Alex Stamos / @alexstamos : The fact that you have to scroll down into the corner of the @washingtonpost's homepage to get to @nakashimae and @craigtimberg's reporting on the SVR compromise of a huge swath of the US government makes me think that official DC hasn't grasped what has happened yet. https://twitter.com/... David Sanger / @sangernyt : Struck by fact that for 6 weeks now @realDonaldTrump and 100+ Republican members of Congress have been talking about a hack that never happened - of the vote. Total silence on the one that did happen: Russian hackers inside the Fed. govt.'s own agencies. https://www.nytimes.com/... Zack Hunt / @zaackhunt : Does it count as hacking if Trump just emailed Putin all of the passwords? https://twitter.com/... Dmitri Alperovitch / @dalperovitch : Last time during the big campaign of 2014-2015, SVR had successfully compromised networks of White House, State Department and the Joint Chiefs of Staff. And that was via simple phishing. They didn't have a nifty backdoor in one of the most popular IT mgmt software around... https://twitter.com/... Rep. Stephanie Murphy / @repstephmurphy : The hard truth is the only way to deter this sort of outrageous but unsurprising Russian conduct is to impose swift and severe costs on Putin that make him think twice before doing this again. Unless there are consequences, this behavior will only continue. https://twitter.com/... Nicholas Kristof / @nickkristof : Good grief. The Department of Homeland Security, in charge of preventing cyber attacks on America, was itself hacked in a major Russian cyber-espionage campaign https://www.washingtonpost.com/ ... Shauna / @goldengateblond : it's like failing to punish them for previous hacks wasn't a deterrent at all https://twitter.com/... Thomas Brewster / @iblametom : DOD declining to comment. Will be huge if they're a victim. It's already huge, of course, now that DHS has been named as the third US gov department breached in these attacks. https://twitter.com/... Thomas Brewster / @iblametom : Veterans Affairs, which has been a big spender on the Orion tool in recent months, says: “VA is looking into this issue and has not detected any breaches. “However, we are taking SolarWinds offline out of an abundance of caution.” https://twitter.com/... Patricia Arquette / @pattyarquette : @LindseyGrahamSC @marcorubio @senatemajldr @MarkMeadows And y'all aren't going to do zip. https://twitter.com/... Barbara Malmet / @b52malmet : Russia has the best hackers. Our Department of Homeland Security is not so secure. https://www.reuters.com/... Catalin Cimpanu / @campuscodi : SolarWinds, the new Blackbaud https://twitter.com/... Eric Geller / @ericgeller : As news breaks about DHS falling victim to this hacking campaign, a U.S. official tells me that there's “massive frustration with CISA on a sluggish response to agency breaches.” According to this official, “incident response teams” meant to assist victim agencies “are delayed.” https://twitter.com/... Thomas Brewster / @iblametom : Update 2: It's not just @CISAgov - US Cyber Command @US_CYBERCOM bought some SolarWinds licenses in 2019 too. https://twitter.com/... Dmitri Alperovitch / @dalperovitch : DHS reportedly compromised by #SolarWinds supply chain hack. Likely one of many victims we are going to hear about in the coming days and weeks https://twitter.com/... Catalin Cimpanu / @campuscodi : Some nice background digging into SolarWinds' US government contracts from Forbes. Customers include CISA, CyberCommand, DOD, FBI, DHS, Veterans Affairs, and many more. No wonder the White House held a National Security Council meeting on Saturday https://twitter.com/... Thomas Brewster / @iblametom : Biggest recent contract renewal was from Veterans Affairs in August for $2.8 million. VA is deeply involved in the Covid-19 US response fwiw. https://twitter.com/... Thomas Brewster / @iblametom : If you don't know much about SolarWinds, it's huge. $6bn+ valuation, customers in almost every vertical imaginable. Just a week ago, it announced the appointment of a new CEO: https://investors.solarwinds.com/ ... https://twitter.com/...

Reuters

Context & Ripple Effects

The DHS intrusion extends a campaign that already had confirmed footholds at Treasury and Commerce via a compromise of SolarWinds' software supply chain. Within days of this report, Sen. Ron Wyden disclosed that Treasury traced the breach of its senior-leadership email system back to July, meaning the attackers were inside federal leadership communications for months before detection.

First-order effects

  • DHS — the department charged with coordinating civilian cyber defense — is itself a victim, and sources indicate national security agencies and defense contractors were compromised too, expanding the blast radius beyond the three publicly named agencies.
  • Agencies that ran SolarWinds products are forced into emergency remediation: Veterans Affairs says it has detected no breach but is taking the software offline as a precaution, a pattern likely repeating across the government.

Second-order effects

  • CISA, which later reporting shows was already underfunded and short on talent while absorbing fallout from two massive cyberattacks, must triage victim identification across agencies it lacks the staff to support.
  • The discovery that Chinese hackers separately exploited another bug in SolarWinds software against a USDA payroll agency turns one vendor's codebase into a shared attack surface for multiple nation-states, forcing every customer to assume any SolarWinds flaw is contested terrain.

Third-order effects

  • Accountability migrates from the attacker to the vendor: the DOJ-Volexity investigation detailed by Wired and the SEC's eventual Wells notices to SolarWinds' CISO and CFO point toward personal legal exposure for security executives whose products are used as espionage vectors.
  • If supply-chain compromise keeps proving cheaper than attacking agencies directly, Congress faces structural questions about mandatory software provenance and disclosure rules for federal vendors, layered atop an existing cybersecurity workforce shortage that constrains any regulatory response.

The trend: Nation-state espionage is shifting from direct attacks on government networks to compromising the commercial software those networks share, letting a single intrusion cascade across many agencies.

Discussion

  • @dnvolz Dustin Volz on x
    Can confirm DHS has also been hacked in the SolarWinds attack. DHS is not currently acknowledging their breach publicly. With Commerce and Treasury, that's three confirmed agency intrusions. I'm also told national security agencies and defense contractors have been compromised.
  • @alexstamos Alex Stamos on x
    The fact that you have to scroll down into the corner of the @washingtonpost's homepage to get to @nakashimae and @craigtimberg's reporting on the SVR compromise of a huge swath of the US government makes me think that official DC hasn't grasped what has happened yet. https://twi…
  • @sangernyt David Sanger on x
    Struck by fact that for 6 weeks now @realDonaldTrump and 100+ Republican members of Congress have been talking about a hack that never happened - of the vote. Total silence on the one that did happen: Russian hackers inside the Fed. govt.'s own agencies. https://www.nytimes.com/.…
  • @zaackhunt Zack Hunt on x
    Does it count as hacking if Trump just emailed Putin all of the passwords? https://twitter.com/...
  • @dalperovitch Dmitri Alperovitch on x
    Last time during the big campaign of 2014-2015, SVR had successfully compromised networks of White House, State Department and the Joint Chiefs of Staff. And that was via simple phishing. They didn't have a nifty backdoor in one of the most popular IT mgmt software around... http…
  • @repstephmurphy Rep. Stephanie Murphy on x
    The hard truth is the only way to deter this sort of outrageous but unsurprising Russian conduct is to impose swift and severe costs on Putin that make him think twice before doing this again. Unless there are consequences, this behavior will only continue. https://twitter.com/..…
  • @nickkristof Nicholas Kristof on x
    Good grief. The Department of Homeland Security, in charge of preventing cyber attacks on America, was itself hacked in a major Russian cyber-espionage campaign https://www.washingtonpost.com/ ...
  • @goldengateblond Shauna on x
    it's like failing to punish them for previous hacks wasn't a deterrent at all https://twitter.com/...
  • @iblametom Thomas Brewster on x
    DOD declining to comment. Will be huge if they're a victim. It's already huge, of course, now that DHS has been named as the third US gov department breached in these attacks. https://twitter.com/...
  • @iblametom Thomas Brewster on x
    Veterans Affairs, which has been a big spender on the Orion tool in recent months, says: “VA is looking into this issue and has not detected any breaches. “However, we are taking SolarWinds offline out of an abundance of caution.” https://twitter.com/...
  • @iblametom Thomas Brewster on x
    Update 2: It's not just @CISAgov - US Cyber Command @US_CYBERCOM bought some SolarWinds licenses in 2019 too. https://twitter.com/...
  • @pattyarquette Patricia Arquette on x
    @LindseyGrahamSC @marcorubio @senatemajldr @MarkMeadows And y'all aren't going to do zip. https://twitter.com/...
  • @b52malmet Barbara Malmet on x
    Russia has the best hackers. Our Department of Homeland Security is not so secure. https://www.reuters.com/...
  • @campuscodi Catalin Cimpanu on x
    SolarWinds, the new Blackbaud https://twitter.com/...
  • @ericgeller Eric Geller on x
    As news breaks about DHS falling victim to this hacking campaign, a U.S. official tells me that there's “massive frustration with CISA on a sluggish response to agency breaches.” According to this official, “incident response teams” meant to assist victim agencies “are delayed.” …
  • @dalperovitch Dmitri Alperovitch on x
    DHS reportedly compromised by #SolarWinds supply chain hack. Likely one of many victims we are going to hear about in the coming days and weeks https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Some nice background digging into SolarWinds' US government contracts from Forbes. Customers include CISA, CyberCommand, DOD, FBI, DHS, Veterans Affairs, and many more. No wonder the White House held a National Security Council meeting on Saturday https://twitter.com/...
  • @iblametom Thomas Brewster on x
    Biggest recent contract renewal was from Veterans Affairs in August for $2.8 million. VA is deeply involved in the Covid-19 US response fwiw. https://twitter.com/...
  • @iblametom Thomas Brewster on x
    If you don't know much about SolarWinds, it's huge. $6bn+ valuation, customers in almost every vertical imaginable. Just a week ago, it announced the appointment of a new CEO: https://investors.solarwinds.com/ ... https://twitter.com/...