/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: state-backed Russian hacking group APT29, or Cozy Bear, is behind the hacks of US Treasury, NTIA, and FireEye

Treasury, Commerce, FireEye—were breached through an IT Management System called Solar Winds https://www.washingtonpost.com/ ... Dustin Volz / @dnvolz : Sen. Angus King says hack is especially bad as it emerges during haphazard presidential transition. Putin “can hire about 8,000 hackers for the price of one jet fighter,” King said. “We just learned the damage those hackers can do, if it is indeed Russia.” https://www.wsj.com/... Chris Bing / @bing_chris : Common refrain from sources: today's news about USG hacks (Commerce + Treasury) and the larger supply chain compromise at Solar Winds, an IT provider for the USG, is “just the tip of the iceberg” This breach is much worse than it appears atm. And it appears very bad already Chris Krebs / @c_c_krebs : If you're a SolarWinds customer & use the below product, assume compromise and immediately activate your incident response team. Odds are you're not affected, as this may be a resource intensive hack. Focus on your Crown Jewels. You can manage this. https://twitter.com/... https://twitter.com/...

Washington Post Ellen Nakashima

Context & Ripple Effects

The attribution lands on a group Washington already had in its sights: US and UK officials named APT29 back in July for ongoing cyberattacks against organizations developing coronavirus vaccines, and Wired documented APT28's broad 2018–2020 campaign against US targets from the GRU side. What changed this week is the vector — sources say Treasury, NTIA and FireEye were reached not through spear-phishing but through a compromise of SolarWinds' IT management system, turning a widely deployed vendor into the delivery mechanism.

First-order effects

  • FireEye, a firm whose business is detecting breaches, is itself a confirmed victim — its own tooling and visibility are now suspect while it investigates.
  • Treasury and Commerce/NTIA are contending with intrusions discovered mid-presidential-transition, which Sen. Angus King argues compounds the damage given haphazard handover oversight.

Second-order effects

  • Every organization running the compromised SolarWinds IT management platform must now treat its own update channel as hostile, forcing emergency audits across government and corporate customers alike.
  • Software vendors face a new trust burden: buyers will demand proof their build and distribution pipelines weren't touched, shifting security spending toward the supply chain rather than the perimeter.

Third-order effects

  • If poisoning trusted software becomes the standard route for state espionage, defense has to move from protecting individual networks to verifying entire vendor ecosystems — an ecosystem-level cyber defense problem no single agency can solve alone.
  • The pattern also shows Russia running distinct units against different target sets — APT28 on political targets, APT29 on intelligence collection — suggesting sustained, specialized operations rather than one-off campaigns.

The trend: State-backed hacking is migrating from direct network intrusion to compromising the trusted software supply chain itself, where one vendor compromise yields thousands of victims.

Discussion

  • @nakashimae Ellen Nakashima on x
    UPDATE: Sources tell me that the victims—Treasury, Commerce, FireEye—were breached through an IT Management System called Solar Winds https://www.washingtonpost.com/ ...
  • @bing_chris Chris Bing on x
    Common refrain from sources: today's news about USG hacks (Commerce + Treasury) and the larger supply chain compromise at Solar Winds, an IT provider for the USG, is “just the tip of the iceberg” This breach is much worse than it appears atm. And it appears very bad already
  • @dnvolz Dustin Volz on x
    Sen. Angus King says hack is especially bad as it emerges during haphazard presidential transition. Putin “can hire about 8,000 hackers for the price of one jet fighter,” King said. “We just learned the damage those hackers can do, if it is indeed Russia.” https://www.wsj.com/...
  • @c_c_krebs Chris Krebs on x
    If you're a SolarWinds customer & use the below product, assume compromise and immediately activate your incident response team. Odds are you're not affected, as this may be a resource intensive hack. Focus on your Crown Jewels. You can manage this. https://twitter.com/... https:…
  • @neusummits Elizabeth Neumann on x
    Relieved that next month we can finally have the head of our government do what cybersecurity professionals have been calling for for years. Attribution and Consequences. https://twitter.com/...
  • @dnvolz Dustin Volz on x
    SOLARWINDS in statement said it is aware of a potential vulnerability related to updates of its Orion technology management software that were released between March and June of this year.