Case file · SOLARWINDS 2020

How the SolarWinds hack happened: malware shipped as a trusted update

Published 2026-09-29 · 5 min read · Missing control: Integrity checks on the build pipeline

In the SolarWinds hack, the malware was delivered by the victims' own software updates, signed and shipped by the vendor itself. SolarWinds said fewer than 18,000 customers may have installed the tainted version of its Orion network monitoring software.[1] This case file covers how attackers slipped code into the company's build system, how a security firm noticed, what it cost, and the one control that would have made the difference.

What happened

SolarWinds, a Texas software company with more than 300,000 customers, sold Orion, a tool IT teams use to watch over their networks.[1] Its forensic teams later traced the earliest suspicious activity on its internal systems to September 2019.[5] In October 2019 a version of Orion went out carrying small, harmless changes that appear to have been a test of whether the intruders could insert code into a release.[5][3]

The test worked. Starting on February 20, 2020, a new injection tool began slipping the real backdoor, later named Sunburst, into Orion builds.[5] Customers who downloaded, installed or updated Orion from March through June 2020 received it.[1] In June 2020 the attackers removed their injection code from the SolarWinds environment, leaving the backdoored updates behind in customer networks.[5]

Months passed before anyone noticed. On December 13, 2020, the security company FireEye published its analysis and SolarWinds acknowledged the breach, and on December 14 SolarWinds told the SEC that fewer than 18,000 customers may have installed the compromised version.[1][2] The Treasury, Commerce and Homeland Security departments were among the victims, and in the end 9 federal agencies were affected.[2][9]

How they got in

SolarWinds never confirmed how the intruders first got in. Its leading theories were a flaw in third-party software, a password-guessing attack or a targeted phishing message.[6] What it did establish was where the damage happened. The malicious code was never in the company's source code repository, where developers store and review their work. It was added inside the build system, the automated process that turns that source code into the finished product customers download.[1][3]

A purpose-built program sat on the build servers and waited for Orion to be compiled. At that moment it quietly swapped in altered source files just before compiling, after developers had already checked in their work. It was designed to stay out of the build logs and avoid causing build errors, so the developers had nothing to notice.[4] Because the finished update came out of SolarWinds' own pipeline, it carried the company's digital signature and looked exactly like a normal release.

Once installed, the backdoor stayed dormant and only woke up for chosen targets. SolarWinds later said fewer than 100 customers had servers that actually communicated with the attackers. Many others never installed the update, or ran it on networks without internet access.[6][3]

How it was caught

No customer or government sensor raised the first flag. FireEye's own staff did, after an alert showed a new phone had been registered to an employee's account for two-step login. When security staff called the employee, he said he had not added any device.[7] Investigators traced the earliest signs of their own compromise back to servers running Orion, pulled apart the software, and found roughly 4,000 lines of hidden code inside a legitimate update.[7]

What it cost

SolarWinds stock fell about 25% after the disclosure, and Orion accounted for roughly 45% of the company's revenue, about $343 million over 9 months of 2020.[1][2] On April 15, 2021, the White House formally attributed the campaign to Russia's foreign intelligence service, the SVR, and the Treasury sanctioned 6 Russian technology firms the same day.[8] A 2022 government audit found that agencies struggled to share information quickly during the response.[9]

In October 2023 the SEC sued SolarWinds and its security chief, saying they misled investors about the company's security. A judge threw out most of the claims in July 2024, and the SEC dropped the rest in November 2025.[10] No one has been charged with the intrusion itself.

The missing control

The missing control: integrity checks on the build pipeline. Nothing independently confirmed that the product coming out of the build system matched the reviewed source code going in.

The attackers chose the one spot between code review and customer delivery where nobody was comparing before and after. A build that is locked down, watched for unexpected processes, and checked against a second, separate build of the same source would have produced a mismatch the first time altered files were slipped in. That could have exposed the October 2019 test run, months before any real backdoor shipped.[5] SolarWinds itself warned afterward that the same weakness could exist in software shops around the world.[4]

What to do in your business

Watch the case
The hack that arrived as a trusted software updateDrops 2026-10-12
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. SEC: SolarWinds Corp Form 8-K, December 14, 2020
  2. Krebs on Security: SolarWinds hack could affect 18K customers
  3. SolarWinds: An investigative update of the cyberattack
  4. Krebs on Security: SolarWinds: What hit us could hit others
  5. SEC: SolarWinds Corp Form 8-K, January 11, 2021
  6. SEC: SolarWinds Corp Form 8-K, May 7, 2021
  7. Dark Reading: FireEye's Mandia: severity-zero alert led to discovery of SolarWinds attack
  8. The Record: White House formally blames Russian intelligence service SVR for SolarWinds hack
  9. FedScoop: Federal agencies struggled to share information in SolarWinds aftermath, GAO finds
  10. Hunton Andrews Kurth: SEC dismisses remainder of SolarWinds case