Security Incidents
SolarWinds SUNBURST
A malicious update distributed through SolarWinds Orion, attributed publicly to a named threat actor, and the disclosure that followed.
What happened
A build system used to produce SolarWinds Orion updates was accessed, and malicious code was injected into the build process so that a signed, trusted update distributed to customers carried a backdoor. The customers were, in effect, installing the compromise themselves.
The affected versions were 2019.4 HF5 through 2020.2.1 HF1. The 2020.2 HF2 and 2020.2.1 HF2 releases removed the trojanised component.
Why it mattered
Three properties combined in a way that had not been seen before at this scale:
- Trust in the distribution channel. The update was signed and delivered through the vendor?셲 normal process. Signature checking did not help, because the signature was valid.
- Concentration. Orion was used for network management by a large number of organisations, including security vendors whose visibility would make a foothold valuable.
- Consequential stolen artefacts. The actor used the access to take security certificates and forge authentication tokens, which turns a network foothold into access to identity providers and cloud services.
Attribution
The attribution to the Russian Foreign Intelligence Service was announced by the Emergency Directive 21-01 memorandum and by parallel statements from the United Kingdom, Canada, Australia, New Zealand, and the European Union, and is repeated in the private-sector analyses cited above. The technical evidence is published in outline; the intelligence that supported the identification is not. As always on this site, an official attribution is recorded as a source claim.
Records
The company?셲 own filings with the US Securities and Exchange Commission are the primary record for what SolarWinds knew, when, and what it cost. The Mandiant analysis and the Microsoft analysis are the primary records for the technical detail. Press summaries should be checked against these.
Sources
- CISA Emergency Directive 21-01 — the directive text and the attribution statement.
- SEC EDGAR: SolarWinds filings — the company?셲 own disclosures.
- Mandiant: Highly Evasive Attacker Leverages SolarWinds Supply Chain — the SUNBURST analysis and the certificate-theft findings.
- Microsoft: Analyzing Solorigate — the GOLDEN SAML and Nobelium analysis, including the timeline back to 2018.
Claim labels
FACT
SolarWinds disclosed on 13 December 2020 that versions 2019.4 HF5 through 2020.2.1 HF1 of Orion had been affected by a compromise of its build and release process.
FACT
CISA issued Emergency Directive 21-01, Mitigate SolarWinds Orion Code Compromise, on 13 December 2020.
FACT
FireEye published an analysis naming the implant SUNBURST on 13 December 2020 and reported that the actor it referred to as UNC2452 had stolen security certificates from multiple organisations to forge SAML tokens.
FACT
Microsoft published an analysis on 18 December 2020 describing the implant under the name GOLDEN SAML and the actor as Nobelium, and stated that the campaign began with test access in 2018 and moved to Orion in 2019.
FACT
SolarWinds SEC filings in December 2020 described the compromise and its own investigation. The company reported significant financial impact in later filings, and the figures evolved across filings; consult the filings rather than summaries.
RESEARCHER ANALYSIS
Multiple independent analyses found that the implant was narrowly targeted, with a filter preventing it from operating on clearly non-target systems, which is consistent with intelligence-collection tradecraft rather than indiscriminate deployment.
SOURCE CLAIM
Attribution to the Russian SVR, the agency responsible for the 2016 theft of security materials attributed to the same service, is made in the United States, United Kingdom, Canada, Australia, New Zealand, and EU statements, and in private-sector analyses. The evidence has not been published in full.
Sources
Last link check: 2026-09-27. A link check confirms reachability, not that every claim has been independently reviewed.
- Emergency Directive 21-01: Mitigate SolarWinds Orion Code Compromise Accessed
- SolarWinds SEC filings (EDGAR company filing index, CIK 1739942) Accessed
- Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor Accessed
- Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers Accessed