Microsoft says the Russian-backed Nobelium group, responsible for the SolarWinds hack, is still targeting global IT supply chain with 14 breaches since May 2021
Microsoft says the Russian-backed Nobelium threat group behind last year's SolarWinds hack is still targeting the global IT supply chain … Source: Microsoft On the Issues .
Context & Ripple Effects
Microsoft had already described SolarWinds as an ongoing campaign that reached more than 40 customers, and later tied the same actors to a malicious-email campaign through a State Department aid agency targeting 150 organizations. The new disclosure shifts the focus from individual victims to IT providers as the route into many downstream networks.
The report also reinforces Microsoft’s earlier call for a global response to the SolarWinds intrusion: compromise of a supplier can extend an attacker’s reach well beyond the initial breach.
First-order effects
- The 14 breached IT providers become immediate pivot points for Nobelium’s access to their customers, raising the urgency of incident review across those providers’ connected environments.
- Microsoft’s disclosure gives customers and security teams a concrete reason to scrutinize supplier-originated software, services, and communications rather than treating SolarWinds as a closed incident.
Second-order effects
- Organizations that depend on affected IT providers face a broader third-party security burden, because the earlier aid-agency email campaign showed how a compromised intermediary can be used to reach many outside groups.
- IT suppliers face greater pressure to demonstrate control over their software-delivery and customer-access paths as buyers reassess the risk concentrated in shared providers.
Third-order effects
- Repeated use of trusted intermediaries points toward software and IT-service delivery becoming a primary security control plane, where supplier assurance matters as much as perimeter defense.
- If this pattern persists, supply-chain resilience will increasingly depend on traceable control over how software, updates, and provider access reach customer networks.
The trend: Nobelium’s reported activity is part of a broader shift in which attackers target high-leverage IT suppliers to scale access across customer ecosystems.