SolarWinds Breach Fallout Keeps Getting Worse
Every day, the information we learn about the FireEye hack just keeps getting increasingly worse.
Last week we wrote about the hack occurring; yesterday we reported that not only was FireEye impacted, but the US government was, as well... Along with businesses and other governments across the globe; and today, we are starting to understand the full scope of the attack, and it's not pretty.
In fact, it now appears that around 18.000 entities were victims of this particular attack. As we mentioned yesterday, the hackers were able to worm their way into systems via the Austin, Texas-based software tools provider, SolarWinds. While it has not been 100% proven, it appears that the most likely culprit was Cozy Bear, a Russian Federal Security Service (FSB) hacking group, though they are, not surprisingly, denying any responsibility.
The responsible party, who is clearly extremely sophisticated, utilized a SolarWinds software update to infect selected victims via a backdoor version of SolarWind's Orion network management tool (which is now being called "Sunburst"). According to a document filed yesterday by SolarWinds, the hackers then used Sunburst to infect customers who installed an update between March to June of this year... which was approximately 18,000 of their 300,000 customers.
Need help implementing these strategies?
Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment
Explore Our Services
Related Service
Protect Your Business with Our Cybersecurity Services
Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.
Explore Cybersecurity Services
Free cybersecurity consultation available
Schedule Now