DOJ: 27 US Attorney offices had at least one staffer's Microsoft email account breached from May to Dec. 2020 by Russian hackers as part of the SolarWinds hack
including Southern District of New York: report Edward Moyer / CNET : SolarWinds hackers nailed federal prosecutors' offices, Department of Justice says Jon Fingas / Engadget : DOJ: Hackers behind SolarWinds attacks targeted federal prosecutors Eileen AJ Connelly / New York Post : Russians hacked 27 US attorney offices, including SDNY Bill Allison / Bloomberg : SolarWinds Hack Reached 27 U.S. Attorneys' Offices, Justice Says Sergiu Gatlan / BleepingComputer : DOJ: SolarWinds hackers breached emails from 27 US Attorneys' offices Associated Press : SolarWinds: Russian hackers broke into email accounts at US attorney offices Dom Calicchio / Fox News : Justice Department says hackers struck 27 US attorneys' offices around US Jordan Williams / The Hill : SolarWinds hackers accessed over two dozen federal prosecutors' offices: DOJ Tweets: Renato Mariotti / @renato_mariotti : Russian hackers broke into email accounts at multiple U.S. Attorney's Offices, according to the DOJ. Those emails could include strategy discussions and non-public details about sensitive investigations, like the investigation of Trump ally Tom Barrack. https://apnews.com/... Eric Tucker / @etuckerap : The department said 80% of Microsoft email accounts used by employees in the four U.S. attorney offices in New York were breached. All told, 27 U.S. Attorney offices had at least one employee's email account compromised in the SolarWinds campaign. https://apnews.com/... Jonathan Lemire / @jonlemire : WASHINGTON (AP) — The Russian hackers behind the massive SolarWinds cyberespionage campaign broke into the email accounts some of the most prominent federal prosecutors' offices around the country last year, the Justice Department said. https://apnews.com/... Michael Edison Hayden / @michaelehayden : Russian hackers behind SolarWinds broke into the email accounts of some of the most prominent federal prosecutors' offices around the U.S., per DOJ. Seems like this should be a bigger story: https://apnews.com/... John Scott-Railton / @jsrailton : WOAH: 🇷🇺 Russia hacked emails of US federal prosecutors around the country. Matches SolarWinds timeframe. Sometimes the best stories are deliberately buried on a Friday evening before holidays... https://apnews.com/... https://twitter.com/... Julia Davis / @juliadavisnews : The Russian hackers behind the massive SolarWinds cyberespionage campaign broke into the email accounts some of the most prominent federal prosecutors' offices around the country last year, the Justice Department said Friday. https://apnews.com/...
Context & Ripple Effects
The DOJ disclosure places federal prosecutors within the broader SolarWinds email-compromise arc. Related coverage had already described attackers using a compromised State Department aid-agency email system to send malicious messages to organizations critical of Putin, making the prosecutors' exposure part of a wider campaign against government-linked communications.
Later coverage adds a separate federal-courts breach investigation and a Microsoft email-system intrusion that affected State Department accounts. Those incidents do not establish the same actor or breach path, but they reinforce the concentration of risk around federal email systems.
First-order effects
- The Justice Department must treat Microsoft email accounts in 27 U.S. Attorney offices as part of the SolarWinds incident’s exposed communications footprint.
- The finding makes federal prosecutors—not only executive-branch aid offices—a documented target set in the Russian campaign.
Second-order effects
- Microsoft faces broader scrutiny of the government email environments implicated across the campaign, following the earlier compromise of a State Department aid-agency email system.
- The DOJ’s disclosure adds urgency to the separate federal-courts breach investigation, because both involve institutions handling sensitive legal and government communications.
Third-order effects
- The sequence of SolarWinds, the courts investigation, and the later State Department email theft points to government email as a recurring high-value target rather than a peripheral administrative system.
- If this pattern persists, federal cyber-risk management will increasingly be judged on the security of shared identity and email layers across agencies, not solely on the security of individual offices.
The trend: Government email and identity systems are becoming a persistent focal point for breaches spanning agencies and threat actors.