Microsoft says compromised SolarWinds apps were on its networks but that no customer data was stolen; it denies report hackers used its systems to attack others
Microsoft's statement lands mid-crisis: the same-day ZDNet report established that compromised SolarWinds binaries had run inside its own environment, and Microsoft's immediate task was damage containment — confirming presence while denying both customer-data theft and that its infrastructure served as a launchpad against others.
The disclosure aged unevenly. Within weeks Microsoft conceded hackers viewed some source code through an employee account (per the New York Times), and by February its completed investigation found stolen source code with no evidence internal systems were abused (ZDNet). By June, an attacker using a customer service agent account had attacked customers during a probe of suspected SolarWinds hackers (Reuters) — making this December statement the first entry in a rolling revision of what 'no impact' meant.
First-order effects
Microsoft customers get an explicit assurance that no customer data was taken, but the confirmation that trojanized SolarWinds apps ran internally forces enterprise buyers to treat every SolarWinds deployment as potentially compromised until proven otherwise.
Microsoft's flat denial that its systems were used to attack others puts it publicly at odds with reporting claiming otherwise, raising the reputational stakes for every subsequent disclosure in the investigation.
Second-order effects
Each walk-back — from 'no customer data' to viewed source code to the customer-service-agent intrusions — hands security rivals and government investigators evidence that vendor self-assessments understate supply-chain breaches, pressuring other affected vendors to disclose faster and more completely.
SolarWinds' customer base faces forced remediation and contract scrutiny regardless of Microsoft's specific findings, since the compromise of a shared update channel makes every downstream user a potential victim.
Third-order effects
The pattern — initial minimal-impact statements progressively revised over six months toward confirmed source-code theft and follow-on customer attacks — points toward regulators and customers treating first-day breach statements as provisional, with sustained independent verification becoming the norm for nation-state-grade incidents.
If trusted software update channels remain the vector of choice, the industry structurally shifts toward treating build-and-distribution pipelines, not endpoints, as the primary security perimeter.
The trend: Major-vendor breach disclosures are becoming multi-month serials, where each investigative milestone revises the earlier 'contained' narrative and resets trust across the software supply chain.
It is now clear that a group of highly sophisticated state-sponsored hackers, likely Berserk Bear, breached Austin's network, using it as infrastructure to stage additional cyberattacks. https://theintercept.com/...
VMware vulnerability a vector in the SolarWinds incident? The company says it has received no notification/indication this is the case, but the timing, MO of the flaw (forging single sign-on tokens) and recent NSA/CSIA advisories seem to suggest otherwise. https://krebsonsecurity…
Important point raised about the strength of the public SVR attribution in this great piece from @dnvolz and @bobmcmillan. The SVR doesn't make much sense IMHO. https://www.wsj.com/... https://twitter.com/...
The suspected Russian hackers were victims of their own success and hubris. After breaching scores of targets undetected for many months, they went after a harder one: a huge cyber firm with vast investigative resources. That led to the hack's unraveling. https://www.wsj.com/...
FireEye CEO Kevin Mandia said the hack of his firm through SolarWinds was like “a sniper round through a bulletproof vest.” Once SolarWinds was suspected, FireEye analysts scoured 50,000 lines of code in search of a “needle in a stack of needles.” https://www.wsj.com/...
“The attack blended extraordinarily stealthy tradecraft, using cyber tools never before seen in a previous attack, with a strategy that zeroed in on a weak link in the software supply chain that all U.S. businesses and government institutions rely on...” https://twitter.com/...
Microsoft president Brad Smith says Reuters report is false. “We have no indication of this.” Microsoft stands by Sunday statement: “We also want to reassure our customers that we have not identified any Microsoft product or cloud service vulnerabilities in these investigations.”…
Second supply chain hack in SolarWinds campaign announced. Microsoft was also breached in the SolarWinds hack operation. Once in Microsoft's network, the company's own “products were then used to further the attacks on others”. Story from @josephmenn https://www.reuters.com/...