/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

SolarWinds' top investors Silver Lake and Thoma Bravo sold a combined $286M worth of stock in the company on Dec. 7, six days before the hack was made public

The timing of the trades raises questions about whether major shareholders used inside information to avoid stark losses after the attack.

Washington Post

Context & Ripple Effects

The Dec. 7 sales sit at the intersection of two threads in the SolarWinds coverage: how long the intrusion lasted, and who bears responsibility. The CEO later said hackers were inside the company's Office 365 email system for at least nine months from December 2019 nine-month Office 365 breach — meaning the window during which insiders could plausibly have known something was wrong stretches back well before the sale date.

What followed gives the timing story its weight: the SEC ultimately charged SolarWinds itself over alleged failures to disclose cybersecurity problems before the hack became public SEC charges against SolarWinds, and sent rare Wells notices to its CISO and CFO Wells notices to the CISO and CFO. A separate line of commentary argues private equity ownership itself degraded the company's security posture private equity's role in degrading SolarWinds' security — which is exactly what makes the pre-disclosure selling by its two largest PE owners more than a routine filing.

First-order effects

  • Silver Lake and Thoma Bravo avoided whatever share of the post-disclosure collapse fell on remaining holders by selling $286M six days before the news broke — the immediate question is whether that timing reflected material non-public knowledge rather than routine rebalancing.

Second-order effects

  • The SEC's enforcement arc — charging the company for pre-breach disclosure failures and issuing Wells notices to the CISO and CFO — keeps pressure on whether the regulator will extend its gaze from the issuer to the investors who traded ahead of disclosure.

Third-order effects

  • If the pattern holds, PE-controlled critical-software vendors face a structural reckoning: ownership models optimized for cost discipline get re-examined as national-security liabilities, and pre-disclosure trading by controlling shareholders becomes a test case for insider-trading enforcement in buyout-backed firms.

The trend: Private equity's stewardship of critical infrastructure software is shifting from a returns story to an accountability story, with regulators working backward from breaches toward disclosure practices and owner behavior.

Discussion

  • @senblumenthal Richard Blumenthal on x
    Stunning. Today's classified briefing on Russia's cyberattack left me deeply alarmed, in fact downright scared. Americans deserve to know what's going on. Declassify what's known & unknown.
  • @jasonhowell Jason Howell on x
    Not strange at all nope not at all https://twitter.com/...
  • @shashj Shashank Joshi on x
    “After initiating the hacks by corrupting patches of widely used network monitoring software, the hackers hid well, wiped away their tracks and communicated through IP addresses in the United States rather than ones in, say, Moscow to minimize suspicions.' https://www.washingtonp…
  • @drewharwell Drew Harwell on x
    New: The two investment firms that own 70% of SolarWinds, the software company at center of Russian mega-breach, sold $280 million in shares just before the hack was revealed (and the stock plunged 22%). Good timing, or ... ? https://www.washingtonpost.com/ ... @dmac1
  • @mollywood Molly Wood on x
    Oh COME ON https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    These are different from the sales made by the company's execs, previously announced part of 10b5-1 plans (see: https://t.co/...). These are legit shady and took place a day before FireEye disclosed its hack too. https://twitter.com/...
  • @biannagolodryga Bianna Golodryga on x
    How is this possible? And how are Russians getting so damn good, so fast? “CISA officials told congressional staff on a Monday evening call that the system did not have the capacity to flag the malware that was signaling back to its Russian masters.” https://www.washingtonpost.co…
  • @msftsecintel @msftsecintel on x
    We're making some updates to detections we released to alert customers about the presence of compromised binaries related to SolarWinds Orion Platform. Starting December 16 at 8:00AM PST, Microsoft Defender Antivirus will block these malicious binaries. https://www.microsoft.com/…
  • @chicagocyber Yoshi on x
    Some companies are about to find out they actually do use SolarWinds in production... https://twitter.com/...
  • @ravivtamir @ravivtamir on x
    Please note: Starting Wednesday, December 16 at 8:00 AM PST, Microsoft Defender Antivirus will begin blocking the known malicious SolarWinds binaries. https://www.microsoft.com/...
  • @campuscodi Catalin Cimpanu on x
    NEW: Microsoft and industry partners seize key domain used in SolarWinds hack Sinkholing efforts underway to identify potential victims and prevent future escalation of compromised networks https://www.zdnet.com/... https://twitter.com/...
  • @mcfaul Michael McFaul on x
    It's time we get serious about cybersecurity. @alexstamos has some ideas: https://twitter.com/...
  • @alexstamos Alex Stamos on x
    Three initial ideas for how Congress and the Biden Administration can respond to the still-developing Russian breach of much of the US Government. https://www.washingtonpost.com/ ...