SolarWinds Hack Cleanup Could Take Months, Cyber-Security Experts Say

Senior US officials and lawmakers have alleged that Russia is to blame for the SolarWinds hacking spree, a charge the Kremlin denies.

Advertisement
By Reuters | Updated: 25 December 2020 09:51 IST
Highlights
  • Hackers managed to access the SolarWinds email system very easily
  • They were able to crossover recently refreshed password protections
  • Hackers crept into US govt networks, including Department of Treasury

Senior US officials and lawmakers have alleged that Russia is to blame for the hacking spree

Cyber-security expert Steven Adair and his team were in the final stages of purging the hackers from a think tank's network earlier this year when a suspicious pattern in the log data caught their eye.

The spies had not only managed to break back in – a common enough occurrence in the world of cyber incident response – but they had sailed straight through to the client's email system, waltzing past the recently refreshed password protections like they didn't exist.

"Wow," Adair recalled thinking in a recent interview. "These guys are smarter than the average bear."

Advertisement

It was only last week that Adair's company - the Reston, Virginia-based Volexity - realized that the bears it had been wrestling with were the same set of advanced hackers who compromised Texas-based software company SolarWinds.

Using a subverted version of the company's software as a makeshift skeleton key, the hackers crept into a swathe of US government networks, including the Departments of Treasury, Homeland Security, Commerce, Energy, State and other agencies besides.

Advertisement

When news of the hack broke, Adair immediately thought back to the think tank, where his team had traced one of the break-in efforts to a SolarWinds server but never found the evidence they needed to nail the precise entry point or alert the company. Digital indicators published by cyber-security company FireEye on December 13 confirmed that the think tank and SolarWinds had been hit by the same actor.

Senior US officials and lawmakers have alleged that Russia is to blame for the hacking spree, a charge the Kremlin denies.

Advertisement

Adair – who spent about five years helping defend NASA from hacking threats before eventually founding Volexity – said he had mixed feelings about the episode. On the one hand, he was pleased that his team's assumption about a SolarWinds connection was right. On the other, they had been at the outer edge of a much bigger story.

A big chunk of the US cyber-security industry is now in the same place Volexity was earlier this year, trying to discover where the hackers have been and eliminate the various secret access points the hackers likely planted on their victims' networks. Adair's colleague Sean Koessel said the company was fielding about 10 calls a day from companies worried that they might have been targeted or concerned that the spies were in their networks.

Advertisement

His advice to everyone else hunting for the hackers: "Don't leave any stone unturned."

Koessel said the effort to uproot the hackers from the think tank - which he declined to identify - stretched from late 2019 to mid-2020 and occasioned two renewed break-ins. Performing the same task across the U.S. government is likely to be many times more difficult.

"I could easily see it taking half a year or more to figure out - if not into the years for some of these organizations," Koessel said.

Pano Yannakogeorgos, a New York University associate professor who served as the founding dean of the Air Force Cyber College, also predicted an extended timeline and said some networks would have to be ripped out and replaced wholesale.

In any case, he predicted a big price tag as caffeinated experts were brought in to pore over digital logs for traces of compromise.

"There's a lot of time, treasury, talent and Mountain Dew that's involved," he said.

© Thomson Reuters 2020


Is MacBook Air M1 the portable beast of a laptop that you always wanted? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  2. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  3. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  4. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. iQOO 15 Live Image Leaked; Company Reveals Display Details
  7. These Realme Phones Will Be Discounted During the Flipkart Big Billion Days Sale
  8. Apple Might Launch the iPhone 17e and Nine Other New Products by Early 2026
  1. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
  2. iQOO 15 Live Image Hints at Design; Confirmed to Feature 2K Samsung AMOLED Display
  3. Vivo Y31 Pro 5G, Vivo Y31 5G Launched in India With 6,500mAh Battery, 50-Megapixel Camera: Price, Features
  4. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones With Dynamic EQ
  5. Flipkart Big Billion Days Sale 2025: Motorola Edge 60 Pro, Edge 60 Fusion, Moto G96 5G and More to Get Discounts
  6. Snapdragon 8 Elite Gen 5 Confirmed to Launch as Qualcomm's Upcoming Flagship Mobile Chipset
  7. Flipkart Big Billion Days Sale: Nothing Announces Offers on Phone 3a Pro, CMF Phone 2 Pro, Nothing Ear, and More
  8. Bitcoin Steadies Above $116,400 as Ether and Other Altcoins Show Resilience
  9. Oppo F31 Pro+ 5G Launched in India With 7,000mAh Battery Alongside Oppo F31 Pro 5G, F31 5G: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.