In a hearing with US lawmakers, ex-SolarWinds CEO blamed an intern for the “solarwinds123” password leak discovered in 2019 that had exposed a SolarWinds server
FireEye CEO on how the SolarWinds hack was discovered — Washington (CNN)Current and former top executives … Tweets: @cnn , @iwillleavenow , @joshelman , @jeffelder , @acdha , @dangillmor , @joeuchill , @internetofshit , @fuzztech , @samnewman , @internetofshit , @joshbal4 , @racheltobac , @h4uk3 , @msuiche , @hexadecim8 , @gregmcneilly , @garius , @sil , @kateoflaherty , @mattmartingft , @ldrogen , and @devblackops Tweets: @cnn : Current and former top executives at SolarWinds are blaming a company intern for a critical lapse in password security that apparently went undiagnosed for years. The password in question, “solarwinds123,” was discovered in 2019 on the public internet. https://www.cnn.com/... Techni-Calli / @iwillleavenow : If an intern's password being publicly discoverable is enough to compromise your entire system, methinks the intern is not the problem here. https://twitter.com/... @joshelman : If you are the leader and you blame the intern for a giant world altering mistake, everyone else should blame you for bad leadership, management, oversight, and training. https://twitter.com/... Jeff Elder / @jeffelder : SolarWinds leaders told Congress today the password “solarwinds123” was a mistake by an intern. An email from the company in 2019 links the issue to “publicly accessible” data and “exposed credentials.” https://www.businessinsider.com/ ... @acdha : Trying to blame an intern for his failures makes me wonder what else hasn't made the news yet: ‘Confronted by Rep. Rashida Tlaib, former SolarWinds CEO Kevin Thompson said the password issue was “a mistake that an intern made.”’ https://www.cnn.com/... Dan Gillmor / @dangillmor : This company should be sued into the ground — and the hedge fund in control should be ruined with it — for installing management that allows an intern to screw up with such consequences. Of course, you have to believe this explanation in the first place, which I do not. https://twitter.com/... Joe Uchill / @joeuchill : Ex CEO Thompson: The “SolarWinds123” password was the fault of an intern who then posted to GitHub. They mitigated the same day they were informed. @internetofshit : if you weren't already ripping solarwinds out of your infrastructure, this sure as hell should be the reason to do it now Nick Selby / @fuzztech : This is beneath contempt. For a CEO to blame an intern for a breach of this impact is utterly cowardly. https://www.cnn.com/... Sam Newman / @samnewman : Another year, another example of a major tech firm blaming a hugely embarrassing failure on a single person. Reminds me of Telstra all over again: https://samnewman.io/.... Plus ça change. https://twitter.com/... @internetofshit : these fuckers throwing the intern under the bus when their entire organization failed to have proper policies or review in place to catch them. if the intern could make an innocent mistake like this, it is *the executives failure* https://twitter.com/... Josh / @joshbal4 : great way of saying “we don't code review or train our interns” 😒 https://twitter.com/... Rachel Tobac / @racheltobac : Instead of blaming an intern's password choice, would love focus on company-wide *technical tools to back people up if and when they make mistakes*. Password managers to store long & random passwords, MFA, patching, etc are a better use of energy here. https://www.cnn.com/... Hauke / @h4uk3 : IT Security is about leadership from the top. So this Is a very bad example. And if an intern can fuck up your security this bad, your processes are fucked up pretty badly. So yeah, blame the intern, CEO https://twitter.com/... Matt Suiche / @msuiche : Great cybersecurity leadership starts with blaming your interns and buying EDRs to solve/justify your problems. What a time to be alive. $SWI https://www.cnn.com/... @hexadecim8 : If you gave an intern the permissions to change a product's password in such a way that it impacts thousands of customers and never audited it, it's not the intern's fault. It's your fault. https://twitter.com/... Greg McNeilly / @gregmcneilly : From the Whitmer school of management. Take no responsibility and throw underlings under the bus (or keyboard). https://twitter.com/... John Bull / @garius : Leadership tip: if you put an INTERN in the position to make this mistake then the failure is yours, not theirs. https://twitter.com/... Stuart Langridge / @sil : I assume that the executives will be giving back all the money they earned from all the things their underpaid interns did correctly. Otherwise that would mean that the intern assumes all the risk while the executives get all the reward, and then what are they being rewarded for? https://twitter.com/... Kate O'Flaherty / @kateoflaherty : I find it amazing that SolarWinds refuses to take any responsibility for the breach. This strategy of repeatedly saying “it's not our fault” is the worst. https://twitter.com/... Matthew Martin / @mattmartingft : I just ... expect more from leaders. https://twitter.com/... Leigh Drogen / @ldrogen : If your company didn't implement a password manager years ago that's a management fuck up, nothing else https://twitter.com/... Brandon Olin / @devblackops : Welcome to our summer internship program! No, we won't pay you, but having the power to disrupt the global software supply chain and cause a massive security incident should even that out. https://twitter.com/...
Context & Ripple Effects
The hearing places SolarWinds’ internal credential controls in the wider breach campaign that had already reached US agencies: related coverage reported state-sponsored access to DHS internal communications after penetrations at Treasury and Commerce. The intern attribution has drawn criticism of SolarWinds leadership, making accountability—not merely the exposed server—a central issue for Congress.
The subsequent assessment that CISA was short on talent and overwhelmed by major attacks gives the exchange added policy weight: supplier-side security lapses and the government’s ability to respond were being examined together.
First-order effects
- SolarWinds’ former CEO assigns responsibility for the 2019 exposure to an intern, while public criticism directly challenges the company leadership’s account of the lapse.
- Congress gains a concrete credential-management failure to scrutinize in its examination of SolarWinds and the broader intrusion campaign.
Second-order effects
- The leadership-blame dispute raises the reputational cost for SolarWinds of presenting a security-control failure as an individual employee error rather than a management issue.
- Federal cyber oversight must weigh vendor security practices alongside CISA’s documented staffing and capacity constraints during large-scale incident response.
Third-order effects
- If supplier breaches continue to reveal basic control failures, congressional and customer scrutiny is likely to center more on executive accountability for security governance, not only technical remediation.
- The pairing of vendor weaknesses with constrained federal response capacity points toward cyber resilience being treated as a shared responsibility across software suppliers and public agencies.
The trend: Major cyber incidents are broadening security accountability from breach detection to the governance practices of software vendors and the capacity of public defenders.