U.S. cybersecurity agency issues rare advisory to 'power down' all servers compromised in massive hack
U.S. officials are scrambling to learn the extent of a potentially massive cyberespionage campaign that infiltrated at least the Treasury and Commerce departments, but they believe they know how the suspected Russian government hackers broke in. The cybersecurity firm FireEye, which disclosed last week that it has been hacked, said late Sunday it has determined the monthlong "global campaign" had been perpetrated via malware inserted in the security update of SolarWinds' popular Orion server management software.
SolarWinds, based in Austin, says its 300,000 customers include the White House, all five branches of the U.S. military, the Pentagon, the State Department, the Justice Department, the National Security Agency, NASA, and the 10 top U.S. telecommunications firms and five leading accounting firms. It attributed the compromised software to a "highly sophisticated, targeted, and manual supply chain attack by a nation state." FireEye said the infected security update appears to have been released in the spring.
The Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) issued a rare directive late Sunday for "all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately." The SolarWinds breach "poses unacceptable risks to the security of federal networks," said acting CISA Director Brandon Wales, "and we urge all our partners — in the public and private sectors — to assess their exposure to this compromise and to secure their networks against any exploitation."
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.
Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
The number of targets was likely limited by the labor-intensive requirements of this particular hack, cybersecurity experts said. But the attack, believed to have been carried out by the APT29 or Cozy Bear arm of Russia's SVR foreign intelligence service, will still likely end up being extensive and damaging.
"This is looking very, very bad," one person familiar with the hack told The Washington Post. "This can turn into one of the most impactful espionage campaigns on record," cybersecurity expert Dmitri Alperovitch told The Associated Press, noting that the Orion software grants remote, "God-mode" access to networks. Another person familiar with the breach told The Wall Street Journal it's a "10" out of 10 in terms of several and national security implications.
Russia's U.S. Embassy denied that Moscow was behind the attacks, calling the allegations "unfounded attempts of the U.S. media to blame Russia."
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Peter has worked as a news and culture writer and editor at The Week since the site's launch in 2008. He covers politics, world affairs, religion and cultural currents. His journalism career began as a copy editor at a financial newswire and has included editorial positions at The New York Times Magazine, Facts on File, and Oregon State University.
-
US port strike averted with tentative labor deal
Speed Read The strike could have shut down major ports from Texas to Maine
By Peter Weber, The Week US Published
-
Biden expected to block Japanese bid for US Steel
Speed Read The president is blocking the $14 billion acquisition of U.S. Steel by Japan's Nippon Steel, citing national security concerns
By Peter Weber, The Week US Published
-
Judges block $25B Kroger-Albertsons merger
Speed Read The proposed merger between the supermarket giants was stalled when judges overseeing two separate cases blocked the deal
By Peter Weber, The Week US Published
-
Rupert Murdoch loses 'Succession' court battle
Speed Read Murdoch wanted to give full control of his empire to son Lachlan, ensuring Fox News' right-wing editorial slant
By Peter Weber, The Week US Published
-
Bitcoin surges above $100k in post-election rally
Speed Read Investors are betting that the incoming Trump administration will embrace crypto
By Peter Weber, The Week US Published
-
Enron mystery: 'sick joke' or serious revival?
Speed Read 23 years after its bankruptcy filing, the Texas energy firm has announced its resurrection
By Peter Weber, The Week US Published
-
US charges Indian tycoon with bribery, fraud
Speed Read Indian billionaire Gautam Adani has been indicted by US prosecutors for his role in a $265 million scheme to secure solar energy deals
By Peter Weber, The Week US Published
-
Boeing machinists approve contract, end strike
Speed Read The company's largest union approved the new contract offer, ending a seven-week strike
By Peter Weber, The Week US Published