Analysis finds 24+ organizations that installed SolarWinds code, including Cisco, Intel, Nvidia, VMware, Belkin, a CA hospital, and Kent State university
A Wall Street Journal analysis identified at least 24 organizations that installed software laced with malicious code by Russian hackers
Wall Street Journal
Context & Ripple Effects
The naming of specific victims turns an abstract incident into a concrete one. Reuters had already reported that under 18,000 SolarWinds customers were compromised between March and June via a poisoned Orion update, with DHS, Treasury, and Commerce among those hit; this Wall Street Journal analysis puts names on the list — Cisco, Intel, Nvidia, VMware, Belkin, a California hospital, and Kent State University — showing the blast radius spans chipmakers, networking vendors, healthcare, and higher education.
The story also sets up two threads the later coverage pulls: investigators went on to find the suspected Russian operation extended well beyond SolarWinds itself, with roughly 30% of victims having no connection to the software, and were probing whether the initial breach came through SolarWinds' engineering offices in Czechia, Poland, and Belarus rather than its US operations.
First-order effects
- Each named organization — Cisco, Intel, Nvidia, VMware, Belkin, the California hospital, Kent State — must now determine what the laced code did inside its network, remediate, and decide how much to disclose to customers, regulators, and users whose data may have been exposed.
- SolarWinds faces an immediate trust collapse among its installed base: the under-18,000 affected customers must treat every Orion update as untrusted until proven clean, freezing or slowing routine patching.
Second-order effects
- Security vendors being victims cuts both ways — organizations that bought Cisco, Intel, or Nvidia products for their own defense now face the uncomfortable question of whether their suppliers' networks were used as a vantage point, forcing every vendor to publish assurance statements about its own environment.
- Scrutiny shifts to SolarWinds' distributed engineering footprint: if the breach entered through its Czech, Polish, or Belarusian offices, other US software companies with offshore development centers face pressure to re-audit access controls and code-signing chains across all locations.
Third-order effects
- If the pattern holds — and Microsoft's later report that Russia-backed Nobelium breached 14 more IT providers since May 2021 suggests it does — the software supply chain itself becomes the primary target, pushing toward regulated build-pipeline attestation and signed-update requirements across the industry.
- The finding that many victims never touched SolarWinds points to a structural shift in espionage tradecraft: initial-access brokers and multiple intrusion paths mean perimeter-based victim lists understate campaigns, reshaping how regulators and insurers define breach scope.
The trend: Nation-state attackers are shifting from exploiting deployed software to poisoning the update pipelines that distribute it, making the software-delivery chain — not the endpoint — the contested ground.
Related: Software-delivery control plane · Under 18,000 SolarWinds customers compromised · Hack extends far beyond SolarWinds · Probe of SolarWinds' Eastern Europe offices · Cisco · Intel
Related Coverage
- View article Axios
- A second hacking group has targeted SolarWinds systems ZDNet · Catalin Cimpanu
- View article CyberScoop
- View article BleepingComputer
- Microsoft has discovered yet more SolarWinds malware TechRadar · Barclay Ballard
- Cisco targeted in SolarWinds attack as Microsoft uncovers a second hacking group SiliconANGLE · Duncan Riley
- View article Axios
- Microsoft details the Solorigate DLL file that was used to install a backdoor in SolarWinds Orion and reveals it discovered additional malware affecting Orion Microsoft Security
- We'll party again next year Protocol · David Pierce
- VMware, Cisco Reveal Impact of SolarWinds Incident SecurityWeek · Eduard Kovacs
- Trump has a ‘blind spot’ for Russia, Mitt Romney said, after the President shifted the focus for the SolarWinds hack from Russia to China Business Insider · Kate Duffy
- FCW Insider: Dec 21 Federal Computer Week
- Sources: WH officials were ready to release a statement on Friday accusing Russia of being “the main actor” in the SolarWinds hack, but were told to stand down Associated Press
Discussion
-
@dnvolz
Dustin Volz
on x
From Cisco, Intel and VMWare to the likes of Kent State University and California hospitals: @WSJ identified infected computers at two dozen organizations that installed the tainted SolarWinds software, showing the wide reach of the suspected Russian hack https://www.wsj.com/...
-
@ericgeller
Eric Geller
on x
Missed this yesterday, but Microsoft said it discovered “an additional malware that also affects the SolarWinds Orion product but has been determined to be likely unrelated to this compromise and used by a different threat actor.” https://www.microsoft.com/... Fun!
-
@ryanaraine
Ryan Naraine
on x
SolarWinds supply chain hack twist: 1. New malware. 2. Unrelated to the known compromise. 3. Used by a different threat actor. 4. New malware is small persistence backdoor that allows remote code execution through SolarWinds web application server https://www.microsoft.com/...
-
@algotrdr
Bill Harts
on x
Mostly for nerds (if you don't know what a DLL is don't bother reading): Fascinating Microsoft analysis of the SolarWinds hack. Surprise ending: MS found ANOTHER, unrelated hack that even affects the SW hack! (Appendix, “Additional malware discovered") https://www.microsoft.com/.…
-
@blackorbird
@blackorbird
on x
#SolarWinds Important Update: 1.About DNS requests https://securelist.com/... decode tool: https://github.com/... 2.Complete attack process https://www.microsoft.com/... https://twitter.com/... https://twitter.com/...
-
@realdonaldtrump
Donald J. Trump
on x
The Cyber Hack is far greater in the Fake News Media than in actuality. I have been fully briefed and everything is well under control. Russia, Russia, Russia is the priority chant when anything happens because Lamestream is, for mostly financial reasons, petrified of....
-
@realdonaldtrump
Donald J. Trump
on x
....discussing the possibility that it may be China (it may!). There could also have been a hit on our ridiculous voting machines during the election, which is now obvious that I won big, making it an even more corrupted embarrassment for the USA. @DNI_Ratcliffe @SecPompeo
-
@thomaswright08
Tom Wright
on x
Trump literally told Xi in person to keep building the concentration camps. https://twitter.com/...
-
@govctw
Governor Christine Todd Whitman
on x
#Putin must have something over #Trump; the President has repeatedly come to Russia's defense, & now we see just how dangerous it is. These cyberattacks go to the heart of our government, putting our country in grave danger are likely worse than we know. https://www.washingtonpos…
-
@richardgrenell
Richard Grenell
on x
“familiar with the speculation” is code for the gossip of the DC crowd. “No special insight” means no access to the actual facts. https://twitter.com/...
-
@ellenychang
Ellen Chang
on x
If you don't follow cybersecurity attacks like me and @john_kreuzer, you should know this is extremely detrimental to security of the U.S. This attack was carefully orchestrated. https://twitter.com/...
-
@john_sipher
John Sipher
on x
This is a terrible breach. Any public retaliation will not be in direct response but we be necessary push back for years of Russian malign activity against the US and its allies. We've mishandled Putin for over a decade. He's now clearly shown his stripes. https://www.nytimes.com…
-
@httech
Hindustan
on x
The number of actual hacking victims has been one of many unanswered questions surrounding the cyber-attack... https://tech.hindustantimes.com/ ...
-
@caseyjohnellis
Cje
on x
i was too busy unpacking this to notice his use of “The Cyber Hack” /me jots notes in the tshirt ideas book https://twitter.com/...
-
@kyledcheney
Kyle Cheney
on x
Nearly all of government is on a war footing, demanding severe consequences for all-but-certain Russian hack — except Trump who provides cover for Russia and connects it to false claim of election hacking. https://twitter.com/...
-
@carlquintanilla
Carl Quintanilla
on x
(Bloomberg) — At least 200 organizations, including government agencies and companies around the world, have been hacked as part of a suspected Russian cyber-attack that implanted malicious code in a widely used software program .. https://www.bloomberg.com/...
-
@debramessing
Debra Messing
on x
Putin is attacking our country from the outside, and Trump is doing it from the inside. Hand in hand. What could be more urgent? https://twitter.com/...
-
@normative
Julian Sanchez
on x
There is absolutely no way anyone can be sure any of this is “well under control.” They're either lying to him or he's lying. https://twitter.com/...
-
@politicalshort
Nick Short
on x
“There was a significant effort to use a piece of third-party software to embed code inside of U.S. Govt systems & it appears systems of private companies & governments across the world as well...we can say pretty clearly that it was the Russians.” -Pompeo https://www.state.gov/.…
-
@nicoleperlroth
Nicole Perlroth
on x
Trump has been pressuring associates to downplay the Russian hack on television, calling it a “hoax” behind closed doors. Latest not so greatest with @SangerNYT https://www.nytimes.com/...
-
@nytpolitics
@nytpolitics
on x
Hours after Mike Pompeo told a conservative radio host that “we can say pretty clearly that it was the Russians” behind the vast hack of the federal government and U.S. industry, President Trump contradicted him and sought to muddy intelligence findings https://www.nytimes.com/..…
-
@brianstelter
Brian Stelter
on x
“Privately, the president has called the hack a ‘hoax’ and pressured associates to downplay its significance and push alternate theories for who is responsible, two people familiar with the exchanges said.” https://www.nytimes.com/...
-
@jimsciutto
Jim Sciutto
on x
This is gross national security malpractice. https://twitter.com/...
-
@luispatino92
Lucho Patio
on x
Do you want to read about the code part of the SolarWind security attack? This is the best post I found about the code that avoided being detected for months and reached some government systems in the USA. #100DaysOfCode https://www.microsoft.com/...
-
@c_c_krebs
Chris Krebs
on x
Do not conflate voting system security and SolarWinds. The proof is in the paper. You can audit or recount again to confirm the outcome. Like they did in Georgia. And Michigan. And Wisconsin. And Arizona. Can't hack paper.
-
@jimsciutto
Jim Sciutto
on x
New: WH officials were preparing to release a statement Friday assigning blame on Russia for recent massive cyberattack but were told to stand down, according to people familiar with plans. @Kevinliptakcnn reporting
-
@senwarren
Elizabeth Warren
on x
I'm gravely concerned about this massive cyberattack. It demands a far more serious response than the President's tweets playing it down and defending Russia. https://www.washingtonpost.com/ ...
-
@levie
Aaron Levie
on x
We're witnessing the criticality of having well staffed, well coordinated, and highly experienced cyber security and technical talent in the government.
-
@ophirgottlieb
Ophir Gottlieb
on x
Hacked Networks will need to be “burned down to the ground” https://apnews.com/... - It's going to take months to kick elite hackers widely believed to be Russian out of the U.S. government networks they have been quietly rifling through since as far back as March.
-
@brento
Brent Ozar
on x
“In an interesting turn of events, the investigation of the whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product” Wow, keeps getting worse. See the “additional malware” section. https://www.microsoft.com/...
-
@file411
@file411
on x
Good LORD: “whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product but has been determined to be likely unrelated to this compromise and used by a different threat actor...” https://www.microsoft.com/... https://tw…
-
@gossithedog
Kevin Beaumont
on x
In depth technical look at SolarWinds nation state activity from MS peeps, including more hunting details etc. Really proud of the teams here, everything been thrown at protecting everyone. https://www.microsoft.com/...
-
@jonathanvswan
Jonathan Swan
on x
Sources briefed on the intelligence say the cyberattack was unequivocally Russia. Bottom line: Pompeo described reality and the president is attacking him for it. https://twitter.com/...
-
@stengel
Richard Stengel
on x
“I think it's the case that now we can say pretty clearly that it was the Russians that engaged in this activity. This was a very significant effort.” Secretary of State Mike Pompeo https://www.nytimes.com/...
-
@andrewsolender
Andrew Solender
on x
Trump breaks his silence on the cyber attack by: - Downplaying its severity - Contradicting his own officials by suggesting it may have been China instead of Russia - Connecting it to his voter fraud conspiracy theories https://twitter.com/...
-
@peterbakernyt
Peter Baker
on x
Trump once again seeks to absolve Russia amid allegations of hostile action, contradicting Pompeo and other US officials by saying Beijing not Moscow may have been behind cyberattack and insisting it was not as a big a deal as reported. @SangerNYT https://www.nytimes.com/...
-
@brianbeutler
Brian Beutler
on x
How will we ever crack the impenetrable Trump-Russia mystery?? https://twitter.com/...
-
@tackettdc
Michael Tackett
on x
“Sec of State Mike Pompeo says Russia was “pretty clearly” behind the gravest cyberattack against the United States on record, the first administration official to publicly tie the Kremlin to the widespread intrusion...when President Trump has kept silent” https://apnews.com/...
-
@geoffrbennett
Geoff Bennett
on x
AP: “Officials at the White House had been prepared to put out a statement Friday afternoon that accused Russia of being ‘the main actor’ in the hack, but were told at the last minute to stand down.” https://apnews.com/...
-
@briankrebs
@briankrebs
on x
45 says all the experts (including his) are wrong: SolarWinds hack is hot air, no big deal. China — not Russia — may be responsible. In same breath, says hack could have affected the election. https://twitter.com/...
-
@jonathanvswan
Jonathan Swan
on x
“A gap is widening between the POTUS and his SecState on this urgent matter of national security. @SecPompeo faces a choice in the coming days — whether to continue to tell the truth about the hack & whether begin to admit reality about the election.” https://www.axios.com/...
-
@homelanddems
@homelanddems
on x
It is completely depraved for President Trump to just now crawl out of his shell to downplay the cyberattack on Fed networks and continue his disinformation campaign. He was silent as Federal agencies spent the last week scrambling to assess the damage. https://www.axios.com/...
-
@repadamschiff
Adam Schiff
on x
Another day, another scandalous betrayal of our national security by this president. Another dishonest tweet that sounds like it could have been written in the Kremlin. Another obsequious display towards Putin. And yet another reason that Trump can't leave office fast enough. htt…
-
@tedlieu
Ted Lieu
on x
Dear @realDonaldTrump: Can you please stop lying? We still don't know the full scale of the damage, and neither do you. But we do know your own @SecPompeo said Russia was behind this massive Cyber Hack. Why do you always bend the knee in front of Putin? What is wrong with you? ht…
-
@wesball
Wes Ball
on x
It's so depressing a chunk of people wanted four more years of this lunacy. https://twitter.com/...
-
@jonathanvswan
Jonathan Swan
on x
As his national security officials gather facts on this cyberattack, President Trump is spending ever-greater amounts of time discussing conspiracy theories with allies including Sidney Powell. https://twitter.com/...
-
@alivelshi
Ali Velshi
on x
It guess “it also could be somebody sitting on their bed that weighs 400 pounds” https://twitter.com/...
-
@asemota
Osaretin Victor Asemota
on x
I like the new Twitter notice. https://twitter.com/...
-
@rubengallego
Ruben Gallego
on x
Voting machines aren't connected to the internet. Your own Secretary of State says it was Russia. It is so weird that you can't bring yourself to say anything bad about Putin or Russia. https://twitter.com/...
-
@margbrennan
Margaret Brennan
on x
The Acting Chairman of Senate Intelligence @marcorubio also attributes the massive hacking of the US government & private industry to Russian intelligence. https://twitter.com/...
-
@gregpmiller
Greg Miller
on x
Keeping his record of protecting/defending Putin in all circumstances intact. https://twitter.com/...
-
@oliverdarcy
Oliver Darcy
on x
Who could have possibly guessed that in his first comment on the massive cyberattack that Trump would attack the media and play down blame on Russia? https://twitter.com/...
-
@pwnallthethings
@pwnallthethings
on x
It is not a big deal and also it is the media's fault, oh wait, no actually it's China's fault, and therefore also a big deal, and also something something something therefore I won the election.
-
@jimsciutto
Jim Sciutto
on x
Now the president is not just silent on Russia and the hack. He is deliberately running defense for the Kremlin by contradicting his own Secretary of State on Russian responsibility. https://twitter.com/...
-
@atrupar
Aaron Rupar
on x
Did Putin write this? https://twitter.com/...
-
@kaitlancollins
Kaitlan Collins
on x
Trump here floats that China may have been responsible for the massive hack of the federal government. Secretary of State Pompeo, tagged here, said yesterday, “We can say pretty clearly that it was the Russians that engaged in this activity.” https://twitter.com/...
-
@laurenwern
Lauren Werner
on x
Putin's orange sock puppet is at it again. https://twitter.com/...
-
@aghamilton29
@aghamilton29
on x
Trump never changes or learns. If people remember, he also dismissed Russia being behind the DNC hack, instead suggestion it could have been a 400 pound guy sitting in his bed. The guy is a clown and the circus is closing in a month. https://twitter.com/...
-
@b_fung
Brian Fung
on x
Trump addresses the hack personally for the first time, says he's been briefed on the incident. https://twitter.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
The president has been telling associates that the Russia hack is a “hoax.” Been trying to confirm this a.m and then he just...tweeted it out... https://twitter.com/...