Disclosed publicly on December 13, 2020, the SolarWinds SUNBURST/Solorigate operation was a Russian foreign-intelligence supply-chain attack in which operatives implanted a malicious component in SolarWinds Orion network-management software updates distributed between March and June 2020. Fewer than 18,000 of roughly 33,000 Orion customers downloaded the trojanized update, including nearly all Fortune 500 companies and U.S. federal agencies such as the Treasury, Commerce, and Homeland Security departments, with follow-on hands-on-keyboard exploitation hitting around 100 private companies and nine federal agencies. The attackers obtained SAML token-signing material that allowed them to forge authentication tokens and pivot into privileged cloud and on-premises systems, prompting CISA's Emergency Directive 21-01 ordering federal agencies to disconnect Orion. Pre-incident security failings later surfaced publicly, including a weak FTP password "solarwinds123" posted on GitHub in November 2019. On October 30, 2023 the SEC charged SolarWinds and CISO Timothy G. Brown with fraud and internal-control failures over concealed cyber risks — the first such enforcement action against a sitting CISO for cyber misrepresentations. On July 18, 2024 S.D.N.Y. Judge Paul A. Engelmayer dismissed most of the SEC's claims but allowed the website-misrepresentation securities-fraud claim to proceed, and in November 2025 the SEC dismissed its remaining claims against both the company and Brown, marking a significant reversal of the enforcement action.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

