https://www.justice.gov/opcl/department-justice-statement-solarwinds-update Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know Dot gov Official websites use .gov A .gov website belongs to an official government organization in the United States. Https Secure .gov websites use HTTPS A lock (A locked padlock) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. The United States Department of Justice The United States Department of Justice Search form Search [ ] [Search] Main menu * About + Budget & Performance + History + Privacy Program * Our Agency + The Attorney General + Organizational Chart + Alphabetical Listing * Topics * News + Videos + Photos + Blogs + Podcasts * Resources + Guidance Documents + Grants + Forms + Publications + Information for Victims in Large Cases + Justice Manual * Careers + Legal Careers + Veteran Recruitment + Disability Hiring * Contact You are here Home >> About DOJ >> Office of Privacy and Civil Liberties Share * Facebook * Twitter * LinkedIn * Digg * Reddit * Pinterest * Email Office of Privacy and Civil Liberties * Office of Privacy and Civil Liberties Home * About the Office + Frequently Asked Questions * Meet the Chief * Privacy Act of 1974 + Overview of the Privacy Act (2020 Edition) + DOJ System of Records Notices + DOJ Computer Matching Agreements + DOJ Privacy Act Regulations + DOJ Privacy Act Requests * Judicial Redress Act of 2015 and the U.S.-EU Data Protection and Privacy Agreement * E-Government Act of 2002 + DOJ Privacy Impact Assessments * Privacy Compliance Process * Resources * Reports * Career Opportunities * Training Opportunities * OPCL FOIA * Contact the Office Department of Justice Statement on SolarWinds Update In a statement issued January 6, 2021, the Department of Justice acknowledged that the global SolarWinds incident involved intrusion into the Department's Microsoft O365 email environment and that this activity constituted a major incident under the Federal Information Security Modernization Act (FISMA). After learning of the malicious activity, the Office of the Chief Information Officer eliminated the identified method by which the actor was accessing the O365 email environment and in accordance with FISMA, the department took steps to notify the appropriate federal agencies, Congress, and the public as warranted. The Department of Justice understands that when victims make information public about the nature and scope of computer intrusions they suffered, others can use that information to prepare themselves for the next threat. To encourage transparency and strengthen homeland resilience, today we are providing additional details about the SolarWinds intrusion in December 2020. The following United States Attorneys' offices had one or more employees' Microsoft O365 email accounts compromised in connection with the SolarWinds incident affecting the U.S. government and the private sector: * Central District of California; * Northern District of California; * District of Columbia; * Northern District of Florida; * Middle District of Florida; * Southern District of Florida; * Northern District of Georgia; * District of Kansas; * District of Maryland; * District of Montana; * District of Nevada; * District of New Jersey; * Eastern District of New York; * Northern District of New York; * Southern District of New York; * Western District of New York; * Eastern District of North Carolina; * Eastern District of Pennsylvania; * Middle District of Pennsylvania; * Western District of Pennsylvania; * Northern District of Texas; * Southern District of Texas; * Western District of Texas; * District of Vermont; * Eastern District of Virginia; * Western District of Virginia; and * Western District of Washington. The Department is responding to this incident as if the Advanced Persistent Threat (APT) group responsible for the SolarWinds breach had access to all email communications and attachments found within the compromised O365 accounts. The APT is believed to have access to compromised accounts from approximately May 7 to December 27, 2020. The compromised data included all sent, received, and stored emails and attachments found within those accounts during that time. While other districts were impacted to a lesser degree, the APT group gained access to the O365 email accounts of at least 80 percent of employees working in the U.S. Attorneys' offices located in the Eastern, Northern, Southern, and Western Districts of New York. The Executive Office for U.S. Attorneys has notified all impacted account holders and the Department has provided guidance to identify particular threats. The Department's objective continues to be mitigating the operational, security, and privacy risks caused by the incident. Updated July 30, 2021 Was this page helpful? Was this page helpful? Yes No Thank you for your input. Contact the Webmaster to submit comments. General Information Office of Privacy and Civil Liberties Leadership Peter A. Winn Acting Chief Privacy and Civil Liberties Officer Kathy Harman-Stokes Acting Director, Office of Privacy and Civil Liberties Contact Office of Privacy and Civil Liberties privacy@usdoj.gov Footer Menu Justice * First Column + en ESPANOL + Contact DOJ * Second Column + Archive + Accessibility + Information Quality + Privacy Policy + Legal Policies & Disclaimers + Social Media * Third Column + Budget & Performance + Office of the Inspector General + No FEAR Act + For Employees + FOIA + USA.gov + Vote.gov U.S. Department of Justice 950 Pennsylvania Avenue, NW Washington, DC 20530-0001 Stay Connected with Justice: Instagram Facebook Twitter YouTube Email Updates Email icon