Microsoft identified 40+ customers targeted in the SolarWinds hack, 80% in the US, says the attack is “ongoing” and calls for a global cybersecurity response
including the highest reaches of the U.S. government — is certain of exactly what the hackers had infiltrated, let alone the full extent of what was taken. https://www.bloomberg.com/... William Turton / @williamturton : New: Members of a consortium of major financial firms that share cybersecurity information with each other and the government, expressed concern the the US govt could be so deeply penetrated that its confidential data could be seen by Russian hackers: https://www.bloomberg.com/... https://twitter.com/... Catalin Cimpanu / @campuscodi : Kaspersky says it “identified approximately ~100 customers who downloaded the trojanized package containing the Sunburst backdoor” Company also said it identified two victims who received 2nd-stage payloads in IOCs posted online by FireEye https://securelist.com/... https://twitter.com/... Shashank Joshi / @shashj : “One of the more chilling developments this year has been what appears to be new steps to use AI to weaponize large stolen datasets about individuals and spread targeted disinformation ... this too will become a permanent part of the threat landscape."' https://blogs.microsoft.com/ ... Shashank Joshi / @shashj : Microsoft: 'This is not “espionage as usual,” even in the digital age. Instead, it represents an act of recklessness that created a serious technological vulnerability for the US and the world" https://blogs.microsoft.com/ ... https://twitter.com/... Tariq Krim / @tariqkrim : According to Microsoft, the recent Slora winds hack has also exposed Europe. It would be good for European institutions to give more details about it. the source is here : https://blogs.microsoft.com/ ... https://twitter.com/... Eric Geller / @ericgeller : Microsoft has identified 40 customers hacked by the suspected Russian operatives after the initial SolarWinds compromise, @BradSmi says. 80% in US, + Canada, Mexico, Belgium, Spain, UK, Israel, & UAE. 44% of victims were in IT, 18% think tank, 18% gov. https://blogs.microsoft.com/ ... https://twitter.com/... Abdullah Saad / @kursed : Most spine chilling read of the day. This is really scary stuff. https://blogs.microsoft.com/ ... Brad Smith / @bradsmi : The latest nation state attack is not espionage as usual, even in the digital age. Instead, it's an act of recklessness that has created a serious and eye-opening vulnerability for the US and the world. Governments and industry must do more. https://blogs.microsoft.com/ ... Andrew S. Weiss / @andrewsweiss : Once again, Microsoft's @BradSmi is taking the lead in saying thoughtful things that rightfully should be coming from a US President and other world leaders https://twitter.com/...
Context & Ripple Effects
This disclosure lands days after FireEye's breach report put the trojanized SolarWinds Orion update on the board, and it is the first hard count from inside the software ecosystem: Microsoft says 40+ customers were targeted, 80% of them in the US, with IT firms, think tanks, and government among the victims. Kaspersky's parallel finding — roughly 100 customers downloaded the Sunburst-backdoored package — suggests the true exposure runs well past any single vendor's view.
The framing matters as much as the number. Microsoft, which had already positioned itself as the private-sector tripwire by warning ~10,000 customers of nation-state attacks in a year, is now describing the intrusion as ongoing and calling for a coordinated global response — a role it would keep playing as the Nobelium campaign stretched on.
First-order effects
- The 40+ targeted customers — mostly US government agencies, IT companies, and think tanks — move from unknown exposure to active incident response, with no one yet certain what was taken versus merely reachable.
- Microsoft's 'ongoing' designation forces every SolarWinds Orion customer worldwide to treat the backdoor as live infrastructure, not a closed incident, and pushes FireEye's IOCs into mandatory triage.
Second-order effects
- Trust in the software update channel itself becomes the casualty: enterprises and the financial-sector information-sharing consortium cited in coverage now have to assume a signed vendor update can be the attack vector, driving demand for the kind of vendor telemetry and threat-notification Microsoft is performing here.
- Rival security vendors like Kaspersky publish their own victim counts and IOC analyses, turning the incident into a multi-vendor attribution race that widens the picture beyond any single company's customer base.
Third-order effects
- The pattern holds and escalates: Nobelium keeps hitting the IT supply chain — 14 providers breached since May 2021 by Microsoft's own count — and by 2024 Microsoft is prioritizing security over new features to counter the same group, showing the 2020 breach became a multi-year structural tax on the industry's largest vendor.
- The attack surface migrates from end targets to the trusted intermediaries between them — update servers, support agents (Microsoft later disclosed a compromised support agent), and managed providers — pushing regulators toward supply-chain security mandates and validating Microsoft's call for a formalized global response.
The trend: Nation-state espionage is shifting from breaching end targets to compromising the trusted software supply chain that connects them, with Microsoft cast as both prime target and de facto global incident responder.