Articles & Research

Briefing

SolarWinds: the supply chain becomes the attack surface

The December 2020 discovery of a compromise inside SolarWinds' Orion software forced a reckoning over trust in the software supply chain.

Marcus Feldman

Cyber Security Lead, American Computer Society

December 2020 · 7 min read

Analysts monitoring threat dashboards in a security operations centre
Analysts monitoring threat dashboards in a security operations centre

In December 2020, security firm FireEye disclosed that it had been breached — and traced the intrusion back to a trojanised update of SolarWinds' widely used Orion network-management software, exposing thousands of organisations, including US federal agencies.

Discovery through an unexpected route

On 8 December 2020, cybersecurity firm FireEye disclosed that nation-state actors had stolen its own red-team assessment tools. Investigating its own breach, FireEye traced the intrusion to a compromised software update from SolarWinds, a Texas-based maker of IT infrastructure management software used by tens of thousands of organisations.

SolarWinds disclosed on 13 December 2020 that a malicious backdoor, later named SUNBURST, had been inserted into builds of its Orion platform distributed between March and June 2020. The trojanised update had been digitally signed with a legitimate SolarWinds certificate, allowing it to bypass standard trust checks.

As many as 18,000 SolarWinds customers had downloaded the compromised update, though the attackers — later attributed by US agencies to Russia's SVR intelligence service — used further access selectively, targeting a smaller number of high-value government and corporate networks.

“The most trusted link in a software supply chain — the signed update — turned out to be the most dangerous.”

A build pipeline as the point of failure

Unlike many prior breaches, SolarWinds did not exploit an application vulnerability directly. Attackers had gained access to SolarWinds' software build environment itself, inserting malicious code during the compilation process so that it shipped inside an otherwise legitimate, signed update.

This meant that every customer trusting the normal update mechanism — precisely the behaviour security guidance usually recommends — was exposed. The incident forced a rethink of the assumption that a signed update from a known vendor is inherently safe.

Consequences and industry response

The US government response included a joint statement from the FBI, CISA, ODNI and NSA in early January 2021 formally attributing the campaign to a Russian state actor, and led to new executive action on software supply-chain security, including requirements for a Software Bill of Materials in federal procurement.

The episode also exposed weaknesses in SolarWinds' internal security practices that predated the attack, prompting broader industry scrutiny of vendor security hygiene as a shared risk across the customer base.

The Society's position

The Society sees SolarWinds as confirmation that software supply-chain integrity must be treated as a core engineering discipline, not an afterthought delegated entirely to vendors.

  • Adopt Software Bill of Materials practices and verify build-pipeline integrity for critical software.
  • Apply zero-trust principles even to signed updates from established vendors.
  • Maintain CPD in secure software supply-chain engineering.
  • Support mandatory breach disclosure and information sharing to shorten detection windows industry-wide.
CybersecuritySoftware engineeringPublic policy

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member