/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: US intel agencies are investigating JetBrains as possible entry point for SolarWinds hackers; JetBrains isn't aware of any investigation or compromise

Russian hackers may have piggybacked on a tool developed by JetBrains, which is based in the Czech Republic

New York Times

Context & Ripple Effects

The SolarWinds inquiry had already expanded from a reported supply-chain attack on its product to investigators examining whether the company’s engineering offices in Czechia, Poland, and Belarus were involved. The latest reporting adds JetBrains, another Czech-based software company, as a possible route under review rather than a confirmed compromised party.

That broader search sits alongside the US agencies’ public assessment that the campaign was likely Russian in origin. JetBrains’ denial of awareness of either an investigation or a compromise makes the distinction between an investigative lead and an established breach central to the story.

First-order effects

  • US intelligence agencies’ SolarWinds investigation now encompasses JetBrains as a possible entry point, while JetBrains faces scrutiny without a reported confirmation of compromise.
  • SolarWinds’ incident investigation must assess a potential route involving a JetBrains tool in addition to the previously reported compromise of its own product.

Second-order effects

  • The widening inquiry forces investigators to map software-tool dependencies around SolarWinds rather than treat the vendor’s reported breach as the campaign’s only relevant access path.
  • JetBrains’ public position puts pressure on the investigation to separate evidence of attackers’ use of a tool from evidence that the toolmaker itself was breached.

Third-order effects

  • If similar probes continue to uncover multiple software dependencies, supply-chain incident response will increasingly center on tracing how widely used development and management tools intersect, not only on the initially breached vendor.
  • The episode reinforces a shift toward treating software suppliers as interconnected security exposure points, with attribution and compromise requiring separate evidence.

The trend: Major cyber investigations are broadening from a single breached supplier to the connected tools and development environments that may have enabled access.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    Exclusive: JetBrains, an obscure software company founded in Russia, based in the Czech Republic, is being investigated as playing a role in the Russian hack. Among its customers are SolarWinds, Google, Siemens, HP, VMWare with @sangernyt @julianbarnes https://www.nytimes.com/...
  • @mshafirov Maxim Shafirov on x
    Is it the way it usually works that one finds out about own investigation from the press? https://twitter.com/...
  • @mattifestation Matt Graeber on x
    When SolarWinds broke, it was backed with detailed context, indicators, and analysis. I know some will disagree but speculation like this about JetBrains without concrete, actionable information is a huge source of uncertainty and confusion. https://twitter.com/...
  • @mshafirov Maxim Shafirov on x
    @Grady_Booch @jetbrains I hope you will have a chance to read our view on it too: https://blog.jetbrains.com/... Your work at Rational was an inspiration for many of us
  • @grady_booch Grady Booch on x
    Egads. I use their Python IDE... Make that “used to use” @jetbrains https://twitter.com/...
  • @dnvolz Dustin Volz on x
    Confirming this. Investigators believe hackers gained access to a TeamCity server used by SolarWinds to build software products, but it is unclear how this system was accessed. “We're not aware of any breach,” JetBrains CEO Maxim Shafirov said. https://www.wsj.com/... https://twi…
  • @chrisrohlf @chrisrohlf on x
    It's almost like people should sit down & understand the technologies before jumping to conclusions. FWIW I explicitly pointed out CI/CD as a scalable vector for supply chain attacks in 2015, and even then I was probably a few years too late to the party. https://blog.jetbrains.c…
  • @kimzetter Kim Zetter on x
    JetBrains says there is nothing to indicate their software was compromised or was used to compromise SolarWinds and no one has suggested this to them directly or contacted them to investigate https://blog.jetbrains.com/...
  • @pt Parker on x
    What a bummer for fans of great IDEs. Back to vim? https://twitter.com/...
  • @hhariri Hadi Hariri on x
    @Grady_Booch @jetbrains Grady, I'd suggest you contrast information before sharing. There's no evidence to this. Here's our statement. https://blog.jetbrains.com/... And if you want an article with more substance, https://www.wsj.com/...
  • @kimzetter Kim Zetter on x
    Investigators examining whether JetBrains, software company founded by 3 Russian engineers in Czech Republic with research labs in Russia, was used as pathway for hackers to insert backdoor into SolarWinds code. JetBrains is used by developers at 300,000 businesses, including SW …
  • @runasand Runa Sandvik on x
    JetBrains says “SolarWinds has not contacted us with any details regarding the breach and the only information we have is what has been made publicly available.” https://blog.jetbrains.com/...
  • @nicoleperlroth Nicole Perlroth on x
    Investigators are still not certain how JetBrains relates to the larger SolarWinds hack, whether it was a parallel way for Russia's attackers to get into government and private systems, or whether it was the original pathway for Russian operatives to first penetrate SolarWinds.
  • @nicoleperlroth Nicole Perlroth on x
    JetBrains is not a household name but is used by 79/ Fortune 100. The product under investigation is TeamCity, which is used by developers to build and test their software. By planting a backdoor in TeamCity, Russia's hackers could have thousands of SolarWinds-style backdoors.
  • @b_fung Brian Fung on x
    I asked DOJ if AG Barr's account was accessed, whether any non-O365 accounts were affected and if DOJ is hunting for any other backdoors potentially left behind. DOJ declined comment except to say it does use non-O365 email in some contexts but only O365 accounts were hit.
  • @b_fung Brian Fung on x
    The Justice Department says up to 3 percent of the agency's Office 365 email accounts were accessed in connection with the SolarWinds hack, which DOJ characterizes as a “major incident”: https://www.justice.gov/...
  • @ericgeller Eric Geller on x
    DOJ announces that it was compromised as part of the SolarWinds hack. The hackers accessed roughly 3% of DOJ employees' Microsoft Office email accounts, according to a statement. “We have no indication that any classified systems were impacted.” https://twitter.com/...
  • @dnvolz Dustin Volz on x
    New: The Justice Department now confirms it has been affected by the SolarWinds hack, says around 3 percent of Microsoft Office email accounts may have been potentially compromised. https://twitter.com/...