Sources: US intel agencies are investigating JetBrains as possible entry point for SolarWinds hackers; JetBrains isn't aware of any investigation or compromise
The SolarWinds inquiry had already expanded from a reported supply-chain attack on its product to investigators examining whether the company’s engineering offices in Czechia, Poland, and Belarus were involved. The latest reporting adds JetBrains, another Czech-based software company, as a possible route under review rather than a confirmed compromised party.
That broader search sits alongside the US agencies’ public assessment that the campaign was likely Russian in origin. JetBrains’ denial of awareness of either an investigation or a compromise makes the distinction between an investigative lead and an established breach central to the story.
First-order effects
US intelligence agencies’ SolarWinds investigation now encompasses JetBrains as a possible entry point, while JetBrains faces scrutiny without a reported confirmation of compromise.
SolarWinds’ incident investigation must assess a potential route involving a JetBrains tool in addition to the previously reported compromise of its own product.
Second-order effects
The widening inquiry forces investigators to map software-tool dependencies around SolarWinds rather than treat the vendor’s reported breach as the campaign’s only relevant access path.
JetBrains’ public position puts pressure on the investigation to separate evidence of attackers’ use of a tool from evidence that the toolmaker itself was breached.
Third-order effects
If similar probes continue to uncover multiple software dependencies, supply-chain incident response will increasingly center on tracing how widely used development and management tools intersect, not only on the initially breached vendor.
The episode reinforces a shift toward treating software suppliers as interconnected security exposure points, with attribution and compromise requiring separate evidence.
The trend: Major cyber investigations are broadening from a single breached supplier to the connected tools and development environments that may have enabled access.
Exclusive: JetBrains, an obscure software company founded in Russia, based in the Czech Republic, is being investigated as playing a role in the Russian hack. Among its customers are SolarWinds, Google, Siemens, HP, VMWare with @sangernyt @julianbarnes https://www.nytimes.com/...
When SolarWinds broke, it was backed with detailed context, indicators, and analysis. I know some will disagree but speculation like this about JetBrains without concrete, actionable information is a huge source of uncertainty and confusion. https://twitter.com/...
@Grady_Booch @jetbrains I hope you will have a chance to read our view on it too: https://blog.jetbrains.com/... Your work at Rational was an inspiration for many of us
Confirming this. Investigators believe hackers gained access to a TeamCity server used by SolarWinds to build software products, but it is unclear how this system was accessed. “We're not aware of any breach,” JetBrains CEO Maxim Shafirov said. https://www.wsj.com/... https://twi…
It's almost like people should sit down & understand the technologies before jumping to conclusions. FWIW I explicitly pointed out CI/CD as a scalable vector for supply chain attacks in 2015, and even then I was probably a few years too late to the party. https://blog.jetbrains.c…
JetBrains says there is nothing to indicate their software was compromised or was used to compromise SolarWinds and no one has suggested this to them directly or contacted them to investigate https://blog.jetbrains.com/...
@Grady_Booch @jetbrains Grady, I'd suggest you contrast information before sharing. There's no evidence to this. Here's our statement. https://blog.jetbrains.com/... And if you want an article with more substance, https://www.wsj.com/...
Investigators examining whether JetBrains, software company founded by 3 Russian engineers in Czech Republic with research labs in Russia, was used as pathway for hackers to insert backdoor into SolarWinds code. JetBrains is used by developers at 300,000 businesses, including SW …
JetBrains says “SolarWinds has not contacted us with any details regarding the breach and the only information we have is what has been made publicly available.” https://blog.jetbrains.com/...
Investigators are still not certain how JetBrains relates to the larger SolarWinds hack, whether it was a parallel way for Russia's attackers to get into government and private systems, or whether it was the original pathway for Russian operatives to first penetrate SolarWinds.
JetBrains is not a household name but is used by 79/ Fortune 100. The product under investigation is TeamCity, which is used by developers to build and test their software. By planting a backdoor in TeamCity, Russia's hackers could have thousands of SolarWinds-style backdoors.
I asked DOJ if AG Barr's account was accessed, whether any non-O365 accounts were affected and if DOJ is hunting for any other backdoors potentially left behind. DOJ declined comment except to say it does use non-O365 email in some contexts but only O365 accounts were hit.
The Justice Department says up to 3 percent of the agency's Office 365 email accounts were accessed in connection with the SolarWinds hack, which DOJ characterizes as a “major incident”: https://www.justice.gov/...
DOJ announces that it was compromised as part of the SolarWinds hack. The hackers accessed roughly 3% of DOJ employees' Microsoft Office email accounts, according to a statement. “We have no indication that any classified systems were impacted.” https://twitter.com/...
New: The Justice Department now confirms it has been affected by the SolarWinds hack, says around 3 percent of Microsoft Office email accounts may have been potentially compromised. https://twitter.com/...