/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says compromised SolarWinds apps were on its networks but that no customer data was stolen; it denies report hackers used its systems to attack others

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

Microsoft's statement lands mid-crisis: the same-day ZDNet report established that compromised SolarWinds binaries had run inside its own environment, and Microsoft's immediate task was damage containment — confirming presence while denying both customer-data theft and that its infrastructure served as a launchpad against others.

The disclosure aged unevenly. Within weeks Microsoft conceded hackers viewed some source code through an employee account (per the New York Times), and by February its completed investigation found stolen source code with no evidence internal systems were abused (ZDNet). By June, an attacker using a customer service agent account had attacked customers during a probe of suspected SolarWinds hackers (Reuters) — making this December statement the first entry in a rolling revision of what 'no impact' meant.

First-order effects

  • Microsoft customers get an explicit assurance that no customer data was taken, but the confirmation that trojanized SolarWinds apps ran internally forces enterprise buyers to treat every SolarWinds deployment as potentially compromised until proven otherwise.
  • Microsoft's flat denial that its systems were used to attack others puts it publicly at odds with reporting claiming otherwise, raising the reputational stakes for every subsequent disclosure in the investigation.

Second-order effects

  • Each walk-back — from 'no customer data' to viewed source code to the customer-service-agent intrusions — hands security rivals and government investigators evidence that vendor self-assessments understate supply-chain breaches, pressuring other affected vendors to disclose faster and more completely.
  • SolarWinds' customer base faces forced remediation and contract scrutiny regardless of Microsoft's specific findings, since the compromise of a shared update channel makes every downstream user a potential victim.

Third-order effects

  • The pattern — initial minimal-impact statements progressively revised over six months toward confirmed source-code theft and follow-on customer attacks — points toward regulators and customers treating first-day breach statements as provisional, with sustained independent verification becoming the norm for nation-state-grade incidents.
  • If trusted software update channels remain the vector of choice, the industry structurally shifts toward treating build-and-distribution pipelines, not endpoints, as the primary security perimeter.

The trend: Major-vendor breach disclosures are becoming multi-month serials, where each investigative milestone revises the earlier 'contained' narrative and resets trust across the software supply chain.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    Hearing Microsoft has no proof of this. https://twitter.com/...
  • @rainnwilson @rainnwilson on x
    In case you didn't know, dozens of governmental orgs were hacked by Russia. This is not fake news. https://www.cnbc.com/...
  • @theintercept @theintercept on x
    It is now clear that a group of highly sophisticated state-sponsored hackers, likely Berserk Bear, breached Austin's network, using it as infrastructure to stage additional cyberattacks. https://theintercept.com/...
  • @dnvolz Dustin Volz on x
    You might call this...rumor control https://twitter.com/...
  • @briankrebs @briankrebs on x
    VMware vulnerability a vector in the SolarWinds incident? The company says it has received no notification/indication this is the case, but the timing, MO of the flaw (forging single sign-on tokens) and recent NSA/CSIA advisories seem to suggest otherwise. https://krebsonsecurity…
  • @crimealytics Jeff Asher on x
    Important point raised about the strength of the public SVR attribution in this great piece from @dnvolz and @bobmcmillan. The SVR doesn't make much sense IMHO. https://www.wsj.com/... https://twitter.com/...
  • @dnvolz Dustin Volz on x
    The suspected Russian hackers were victims of their own success and hubris. After breaching scores of targets undetected for many months, they went after a harder one: a huge cyber firm with vast investigative resources. That led to the hack's unraveling. https://www.wsj.com/...
  • @dnvolz Dustin Volz on x
    FireEye CEO Kevin Mandia said the hack of his firm through SolarWinds was like “a sniper round through a bulletproof vest.” Once SolarWinds was suspected, FireEye analysts scoured 50,000 lines of code in search of a “needle in a stack of needles.” https://www.wsj.com/...
  • @carter_pe Phillip Carter on x
    “The attack blended extraordinarily stealthy tradecraft, using cyber tools never before seen in a previous attack, with a strategy that zeroed in on a weak link in the software supply chain that all U.S. businesses and government institutions rely on...” https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    Microsoft president Brad Smith says Reuters report is false. “We have no indication of this.” Microsoft stands by Sunday statement: “We also want to reassure our customers that we have not identified any Microsoft product or cloud service vulnerabilities in these investigations.”…
  • @kimzetter Kim Zetter on x
    Second supply chain hack in SolarWinds campaign announced. Microsoft was also breached in the SolarWinds hack operation. Once in Microsoft's network, the company's own “products were then used to further the attacks on others”. Story from @josephmenn https://www.reuters.com/...