https://www.wired.com/story/solarwinds-hack-public-disclosure/ Skip to main content Open Navigation Menu To revist this article, visit My Profile, then View saved stories. Close Alert WIRED The DOJ Detected the SolarWinds Hack 6 Months Earlier Than First Disclosed * Backchannel * Business * Culture * Gear * Ideas * Science * Security More To revist this article, visit My Profile, then View saved stories. Close Alert Sign In Search * Backchannel * Business * Culture * Gear * Ideas * Science * Security * Podcasts * Video * Artificial Intelligence * Climate * Games * Newsletters * Magazine * Events * Wired Insider * Jobs * Coupons The SolarWinds Corp. logo is seen on a sign at the headquarters Photograph: SUZANNE CORDEIRO/Getty Images Kim Zetter Security Apr 28, 2023 2:01 PM The DOJ Detected the SolarWinds Hack 6 Months Earlier Than First Disclosed In May 2020, the US Department of Justice noticed Russian hackers in its network but did not realize the significance of what it had found for six months. * * * * * * * * The US Department of Justice, Mandiant, and Microsoft stumbled upon the SolarWinds breach six months earlier than previously reported, WIRED has learned, but were unaware of the significance of what they had found. The breach, publicly announced in December 2020, involved Russian hackers compromising the software maker SolarWinds and inserting a backdoor into software served to about 18,000 of its customers. That tainted software went on to infect at least nine US federal agencies, among them the Department of Justice (DOJ), the Department of Defense, Department of Homeland Security, and the Treasury Department, as well as top tech and security firms including Microsoft, Mandiant, Intel, Cisco, and Palo Alto Networks. The hackers had been in these various networks for between four and nine months before the campaign was exposed by Mandiant. WIRED can now confirm that the operation was actually discovered by the DOJ six months earlier, in late May 2020--but the scale and significance of the breach wasn't immediately apparent. Suspicions were triggered when the department detected unusual traffic emanating from one of its servers that was running a trial version of the Orion software suite made by SolarWinds, according to sources familiar with the incident. The software, used by system administrators to manage and configure networks, was communicating externally with an unfamiliar system on the internet. The DOJ asked the security firm Mandiant to help determine whether the server had been hacked. It also engaged Microsoft, though it's not clear why the software maker was also brought onto the investigation. It's not known what division of the DOJ experienced the breach, but representatives from the Justice Management Division and the US Trustee Program participated in discussions about the incident. The Trustee Program oversees the administration of bankruptcy cases and private trustees. The Management Division advises DOJ managers on budget and personnel management, ethics, procurement, and security. Investigators suspected the hackers had breached the DOJ server directly, possibly by exploiting a vulnerability in the Orion software. They reached out to SolarWinds to assist with the inquiry, but the company's engineers were unable to find a vulnerability in their code. In July 2020, with the mystery still unresolved, communication between investigators and SolarWinds stopped. A month later, the DOJ purchased the Orion system, suggesting that the department was satisfied that there was no further threat posed by the Orion suite, the sources say. A DOJ spokesperson confirmed that the incident and investigation occurred but wouldn't provide any details about what investigators concluded. "While the incident response and mitigation effort was completed, the FBI's criminal investigation remained open throughout," the spokesperson wrote in an email. WIRED confirmed with sources that Mandiant, Microsoft, and SolarWinds were involved in discussions about the incident and investigation. All three companies declined to discuss the matter. The DOJ told WIRED that it notified the US Cybersecurity and Infrastructure Agency (CISA) about the breach at the time it occurred--though a US National Security Agency spokesperson expressed frustration that the agency was not also notified. But in December 2020, when the public learned that a number of federal agencies were compromised in the SolarWinds campaign--the DOJ among them--neither the DOJ nor CISA revealed to the public that the operation had unknowingly been found months earlier. The DOJ initially said its chief information officer had discovered the breach on December 24. Most Popular * Steven Yeun screaming from a car window as Danny in Beef Culture The 45 Best Shows on Netflix Right Now WIRED Staff * [undefined] Gear The 16 Best (and Worst) Mattresses You Can Buy Online Jeffrey Van Camp * [undefined] Gear The 13 Best Electric Bikes for Every Kind of Ride Adrienne So * [undefined] Gear The Best Barefoot Shoes for Walking or Running Scott Gilbertson * In November 2020, months after the DOJ completed the mitigation of its breach, Mandiant discovered that it had been hacked, and traced its breach to the Orion software on one of its servers the following month. An investigation of the software revealed that it contained a backdoor that the hackers had embedded in the Orion software while it was being compiled by SolarWinds in February 2020. The tainted software went out to about 18,000 SolarWinds customers, who downloaded it between March and June, right around the time the DOJ discovered the anomalous traffic exiting its Orion server. The hackers chose only a small subset of these to target for their espionage operation, however. They burrowed further into the infected federal agencies and about 100 other organizations, including technology firms, government agencies, defense contractors, and think tanks. Mandiant itself got infected with the Orion software on July 28, 2020, the company told WIRED, which would have coincided with the period that the company was helping the DOJ investigate its breach. When asked why, when the company announced the supply-chain hack in December, it didn't publicly disclose that it had been tracking an incident related to the SolarWinds campaign in a government network months earlier, a spokesperson noted only that "when we went public, we had identified other compromised customers." The incident underscores the importance of information-sharing among agencies and industry, something the Biden administration has emphasized. Although the DOJ had notified CISA, a spokesperson for the National Security Agency told WIRED that it didn't learn of the early DOJ breach until January 2021, when the information was shared in a call among employees of several federal agencies. That was the same month the DOJ--whose 100,000-plus employees span multiple agencies including the FBI, Drug Enforcement Agency, and US Marshals Service--publicly revealed that the hackers behind the SolarWinds campaign had possibly accessed about 3 percent of its Office 365 mailboxes. There are conflicting reports about whether this attack was part of the SolarWinds campaign or carried out by the same actors. Six months later, the department expanded on this and announced that the hackers had managed to breach email accounts of employees at 27 US Attorneys' offices, including ones in California, New York, and Washington, DC. In its latter statement, the DOJ said that to "encourage transparency and strengthen homeland resilience," it wanted to provide new details, including that the hackers were believed to have had access to compromised accounts from about May 7 to December 27, 2020. And the compromised data included "all sent, received, and stored emails and attachments found within those accounts during that time." The investigators of the DOJ incident weren't the only ones to stumble upon early evidence of the breach. Around the same time of the department's investigation, security firm Volexity, as the company previously reported, was also investigating a breach at a US think tank and traced it to the organization's Orion server. Later in September, the security firm Palo Alto Networks also discovered anomalous activity in connection with its Orion server. Volexity suspected there might be a backdoor on its customer's server but ended the investigation without finding one. Palo Alto Networks contacted SolarWinds, as the DOJ had, but in that case as well, they failed to pinpoint the problem. Senator Ron Wyden, an Oregon Democrat who has been critical of the government's failure to prevent and detect the campaign in its early stages, says the revelation illustrates the need for an investigation into how the US government responded to the attacks and missed opportunities to halt it. "Russia's SolarWinds hacking campaign was only successful because of a series of cascading failures by the US government and its industry partners," he wrote in an email. "I haven't seen any evidence that the executive branch has thoroughly investigated and addressed these failures. The federal government urgently needs to get to the bottom of what went wrong so that in the future, backdoors in other software used by the government are promptly discovered and neutralized." Get More From WIRED * Understand AI advances with our Fast Forward newsletter * Our new podcast wants you to Have a Nice Future * The Arctic's permafrost-obsessed methane detectives * What's AGI, and why are AI experts skeptical? * Hacker group names are now absurdly out of control * A final plea from one of Netflix's abandoned DVDs * The radical, expansive future of period technology * Snap into spring with the Gear team's picks for the best camera bags, fun instant cameras, and mirrorless cameras Kim Zetter writes about cybersecurity and national security and is the author of Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon. * * TopicscybersecuritysecurityhackingRussiahacks More from WIRED Close-up of a person's hand holding an Apple AirTag Are You Being Tracked by an AirTag? Here's How to Check If you're worried that one of Apple's trackers is following you without consent, try these tips. Reece Rogers Illustration of a jail window in the shape of a chat bubble, with the bars bent The Hacking of ChatGPT Is Just Getting Started Security researchers are jailbreaking large language models to get around safety rules. Things could get much worse. Matt Burgess Matt Walsh speaking at a podium during a rally. The Hacker Who Hijacked Matt Walsh's Twitter Was Just 'Bored' The breach of the right-wing provocateur was simply a way of "stirring up some drama," the attacker tells WIRED. But the damage could have been much worse. Dell Cameron Giant brass fly art object on top of a map A Tiny Blog Took on Big Surveillance in China--and Won Digging through manuals for security cameras, a group of gearheads found sinister details and ignited a new battle in the US-China tech war. Amos Zeeberg Green balls connected to each other by wire, on a red backdrop How ChatGPT--and Bots Like It--Can Spread Malware Generative AI is a tool, which means it can be used by cybercriminals, too. Here's how to protect yourself. David Nield Many old routers stacked on top of each other Used Routers Often Come Loaded With Corporate Secrets More than half of the enterprise routers researchers bought secondhand hadn't been wiped, exposing sensitive info like login credentials and customer data. Lily Hay Newman A Chinese paramilitary police officer Chinese Cops Ran Troll Farm and Secret NY Police Station, US Says Three criminal cases detail China's alleged attempts to extend its security forces' influence online--and around the globe. Andy Greenberg macbook Apple's Macs Have Long Escaped Ransomware. That May Be Changing The discovery of malicious encryptors for Apple computers could herald new risks for macOS users if the malware continues to evolve. Lily Hay Newman WIRED WIRED is where tomorrow is realized. It is the essential source of information and ideas that make sense of a world in constant transformation. The WIRED conversation illuminates how technology is changing every aspect of our lives--from culture to business, science to design. The breakthroughs and innovations that we uncover lead to new ways of thinking, new connections, and new industries. * * * * * * More From WIRED * Subscribe * Newsletters * FAQ * Wired Staff * Press Center * Coupons * Editorial Standards * Black Friday * Archive Contact * Advertise * Contact Us * Customer Care * Jobs * RSS * Accessibility Help * Conde Nast Store * Conde Nast Spotlight * Do Not Sell My Personal Info (c) 2023 Conde Nast. All rights reserved. Use of this site constitutes acceptance of our User Agreement and Privacy Policy and Cookie Statement and Your California Privacy Rights. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Conde Nast. Ad Choices Select international siteUnited States * UK * Italia * Japon