Sources: investigators are checking if SolarWinds was hacked via its offices in Czechia, Poland, and Belarus, where the company moved much of its engineering
Those behind the widespread intrusion into government and corporate networks exploited seams in U.S. defenses and gave away nothing to American monitoring of their systems.
New York Times
Context & Ripple Effects
The inquiry follows reports that the Treasury breach involved a flaw in a SolarWinds product, which the company characterized as a supply-chain attack. Investigators are now examining whether SolarWinds' engineering operations in Czechia, Poland, and Belarus were an entry path rather than treating the product flaw as the only relevant point of compromise.
Related coverage subsequently widened the search to a possible JetBrains entry point and found the suspected campaign reached victims without SolarWinds connections. That makes the engineering-office inquiry consequential: it tests whether the incident was a vendor-specific breach or part of a broader intrusion campaign.
First-order effects
SolarWinds' engineering offices in Czechia, Poland, and Belarus become part of investigators' immediate evidence-gathering, placing the company's distributed development environment under scrutiny.
U.S. government and corporate organizations affected by the intrusion face an investigation that is testing potential compromise paths beyond the SolarWinds product itself.
Second-order effects
SolarWinds customers and incident responders must account for the possibility of multiple entry paths while investigators assess the company's engineering footprint and the related JetBrains lead.
Software vendors that distribute widely used tools face greater pressure to show that their development operations, not only released products, are secured against supply-chain compromise.
Third-order effects
If the investigation continues to identify entry paths beyond a single vendor product, breach response will increasingly center on interdependent development and software-supply-chain environments rather than a single compromised update.
The later finding that some victims lacked SolarWinds connections points toward threat investigations organized around attacker infrastructure and access methods, not only around the first identified vendor.
The trend: Major cyber investigations are shifting from isolating a compromised product to mapping the distributed engineering, supplier, and customer pathways through which an intrusion can spread.
Russia isn't just breaking into **250 federal government networks** for no reason. This is INCREDIBLY DANGEROUS and Donald Trump isn't saying a word about it but installed cronies atop our NatSec institutions that are ignoring everything. https://www.nytimes.com/...
Trump plans to issue three cyber-related “presidential determinations” soon, one of which transfers some authority from DoD to CISA, per new CNN story. Also in here: Trump appointees have been asking how SolarWinds intrusions could hurt him politically. https://www.cnn.com/... ht…
Huge👇 “Those questions have taken on particular urgency given that the breach was not detected by any of the government agencies that share responsibility for cyberdefense — [DoD, NSA, DHS] — but by a private cybersecurity company, FireEye.” https://www.nytimes.com/...
This just shouldn't happen: “Some of the compromised SolarWinds software was engineered in Eastern Europe, and American investigators are now examining whether the incursion originated there, where Russian intelligence operatives are deeply rooted.” https://www.nytimes.com/...
None of the SolarWinds customers contacted by The New York Times in recent weeks were aware they were reliant on software that was maintained in Eastern Europe. Many said they did not even know they were using SolarWinds software until the breach.
My point over the last year, that centralized control and monitoring of IT infrastructure is a fundamentally flawed security philosophy has been given a substantial bit of weight by this hack. https://twitter.com/...
New: As US officials grapple w/ fallout from hack of government & private sector systems, questions are swirling about whether the agency tasked with protecting the nation from cyberattacks is up to the job. First story of 2021 w/ @vmsalama & @b_fung https://www.cnn.com/...
Very well-sourced and professional reporting by @SangerNYT, @nicoleperlroth, and @julianbarnes. Difficult to come up with the right metaphor or analogy, but fair to say that Russian spies have secretly been roaming through government offices since March. https://www.nytimes.com/.…
1/ When I pointed out supply chain weaknesses in the voting machine industry in 2019 I didn't have the software supply chain specifically in mind, but, yes, we had better start treating these technologies with the seriousness they deserve: https://twitter.com/... https://twitter.…
Time and time again, Moscow is able to take advantage when the US focus is elsewhere. The hack affected 250+ federal agencies and businesses was “aimed not at the election system but at the rest of the US government and many large American corporations.” https://www.nytimes.com/.…
DUCK ME “breach is far broader than first believed...Russia sent its probes only into a few dozen of the 18,000 government and private networks..it now appears Russia exploited multiple layers of the supply chain to gain access to as many as 250 networks” https://www.nytimes.com/…
Burn it all down. “Some security experts said that ridding so many sprawling federal agencies of the S.V.R. may be futile and that the only way forward may be to shut systems down and start anew” https://www.nytimes.com/...
New deep dive with @SangerNYT on the SolarWinds hack found its 5-6X broader than initially believed with ~250 victims (MSFT tallied 40 initially). -The backdoored Orion software was built/maintained in Eastern Europe. -Concern another major vector used. https://www.nytimes.com/..…
“This is looking much, much worse than I first feared.” As U.S. officials learn more about Russia's cyberattack, the scale of the damage continues to grow. https://www.nytimes.com/...
October 2019!!! It is becoming increasingly clear that missing this hack is one of the Trump Administration's largest & most consequential failures. 2nd only to COVID mismanagement. “The SolarWinds hacking, which began as early as October 2019,” https://www.nytimes.com/...
“SolarWinds moved much of its engineering to satellite offices in the Czech Republic, Poland, and Belarus, were engineers had broad access to the Orion network management software that Russia's agents compromised.” Seriously, I can't. https://www.nytimes.com/...
“American officials responsible for cybersecurity are now consumed by what they missed for 9 months: a hacking, now believed to have affected upward of 250 federal agencies, that Russia aimed not at the election but at the rest of the US government.” https://www.nytimes.com/...
After initially issuing a statement that dismissed reports that it had been hacked, Microsoft now admits that hackers breached its network and viewed (but didn't modify) its products' source code as part of the SolarWinds affair. https://msrc-blog.microsoft.com/ ...
New: Microsoft says #SolarWinds hackers were able to access “a number of source code repositories.” However, the company adds that it “found no indications that our systems were used to attack others.” https://msrc-blog.microsoft.com/ ... https://twitter.com/...
Microsoft Says Russian Hackers Viewed Some of Its Source Code. The hackers gained more access than the company previously revealed, though the attackers were unable to modify code or access emails. https://www.nytimes.com/...