U.S. cybersecurity agency issues rare advisory to 'power down' all servers compromised in massive hack


U.S. officials are scrambling to learn the extent of a potentially massive cyberespionage campaign that infiltrated at least the Treasury and Commerce departments, but they believe they know how the suspected Russian government hackers broke in. The cybersecurity firm FireEye, which disclosed last week that it has been hacked, said late Sunday it has determined the monthlong "global campaign" had been perpetrated via malware inserted in the security update of SolarWinds' popular Orion server management software.
SolarWinds, based in Austin, says its 300,000 customers include the White House, all five branches of the U.S. military, the Pentagon, the State Department, the Justice Department, the National Security Agency, NASA, and the 10 top U.S. telecommunications firms and five leading accounting firms. It attributed the compromised software to a "highly sophisticated, targeted, and manual supply chain attack by a nation state." FireEye said the infected security update appears to have been released in the spring.
The Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) issued a rare directive late Sunday for "all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately." The SolarWinds breach "poses unacceptable risks to the security of federal networks," said acting CISA Director Brandon Wales, "and we urge all our partners — in the public and private sectors — to assess their exposure to this compromise and to secure their networks against any exploitation."
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.

Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
The number of targets was likely limited by the labor-intensive requirements of this particular hack, cybersecurity experts said. But the attack, believed to have been carried out by the APT29 or Cozy Bear arm of Russia's SVR foreign intelligence service, will still likely end up being extensive and damaging.
"This is looking very, very bad," one person familiar with the hack told The Washington Post. "This can turn into one of the most impactful espionage campaigns on record," cybersecurity expert Dmitri Alperovitch told The Associated Press, noting that the Orion software grants remote, "God-mode" access to networks. Another person familiar with the breach told The Wall Street Journal it's a "10" out of 10 in terms of several and national security implications.
Russia's U.S. Embassy denied that Moscow was behind the attacks, calling the allegations "unfounded attempts of the U.S. media to blame Russia."
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Peter has worked as a news and culture writer and editor at The Week since the site's launch in 2008. He covers politics, world affairs, religion and cultural currents. His journalism career began as a copy editor at a financial newswire and has included editorial positions at The New York Times Magazine, Facts on File, and Oregon State University.
-
Book reviews: 'America, América: A New History of the New World' and 'Sister, Sinner: The Miraculous Life and Mysterious Disappearance of Aimee Semple McPherson'
Feature A historian tells a new story of the Americas and the forgotten story of a pioneering preacher
-
Another messaging app used by the White House is in hot water
The Explainer TeleMessage was seen being used by former National Security Adviser Mike Waltz
-
AI hallucinations are getting worse
In the Spotlight And no one knows why it is happening
-
Warren Buffet announces surprise retirement
speed read At the annual meeting of Berkshire Hathaway, the billionaire investor named Vice Chairman Greg Abel his replacement
-
Trump calls Amazon's Bezos over tariff display
Speed Read The president was not happy with reports that Amazon would list the added cost from tariffs alongside product prices
-
Markets notch worst quarter in years as new tariffs loom
Speed Read The S&P 500 is on track for its worst month since 2022 as investors brace for Trump's tariffs
-
Tesla Cybertrucks recalled over dislodging panels
Speed Read Almost every Cybertruck in the US has been recalled over a stainless steel panel that could fall off
-
Crafting emporium Joann is going out of business
Speed Read The 82-year-old fabric and crafts store will be closing all 800 of its stores
-
Trump's China tariffs start after Canada, Mexico pauses
Speed Read The president paused his tariffs on America's closest neighbors after speaking to their leaders, but his import tax on Chinese goods has taken effect
-
Chinese AI chatbot's rise slams US tech stocks
Speed Read The sudden popularity of a new AI chatbot from Chinese startup DeepSeek has sent U.S. tech stocks tumbling
-
US port strike averted with tentative labor deal
Speed Read The strike could have shut down major ports from Texas to Maine