Suspected Chinese hackers used SolarWinds bug to spy on US payroll agency – sources | The Business Standard
Skip to main content
  • Epaper
  • Economy
    • Aviation
    • Banking
    • Bazaar
    • Budget
    • Industry
    • NBR
    • RMG
    • Corporates
  • Stocks
  • Analysis
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Friday
May 30, 2025

Sign In
Subscribe
  • Epaper
  • Economy
    • Aviation
    • Banking
    • Bazaar
    • Budget
    • Industry
    • NBR
    • RMG
    • Corporates
  • Stocks
  • Analysis
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
FRIDAY, MAY 30, 2025
Suspected Chinese hackers used SolarWinds bug to spy on US payroll agency – sources

World+Biz

Reuters
03 February, 2021, 03:20 pm
Last modified: 03 February, 2021, 03:26 pm

Related News

  • Mob beating kills 2 in Ctg: What's been revealed
  • As China hacking threat builds, Biden to order tougher cybersecurity standards
  • Chinese cyberattacks on Taiwan government averaged 2.4 mln a day in 2024: report
  • Chinese hack of US Treasury breached sanctions office: Washington Post
  • US Treasury says Chinese hackers stole documents in 'major incident'

Suspected Chinese hackers used SolarWinds bug to spy on US payroll agency – sources

Two people briefed on the case said FBI investigators recently found that the National Finance Center, a federal payroll agency inside the US Department of Agriculture, was among the affected organisation

Reuters
03 February, 2021, 03:20 pm
Last modified: 03 February, 2021, 03:26 pm
FILE PHOTO: SolarWinds Corp. banner hangs at the New York Stock Exchange (NYSE) on the IPO day of the company in New York, U.S., October 19, 2018. REUTERS/Brendan McDermid
FILE PHOTO: SolarWinds Corp. banner hangs at the New York Stock Exchange (NYSE) on the IPO day of the company in New York, U.S., October 19, 2018. REUTERS/Brendan McDermid

Suspected Chinese hackers exploited a flaw in software made by SolarWinds Corp to help break into US government computers last year, five people familiar with the matter told Reuters, marking a new twist in a sprawling cybersecurity breach that US lawmakers have labelled a national security emergency.

Two people briefed on the case said FBI investigators recently found that the National Finance Center, a federal payroll agency inside the US Department of Agriculture, was among the affected organisations, raising fears that data on thousands of government employees may have been compromised.

The software flaw exploited by the suspected Chinese group is separate from the one the United States has accused Russian government operatives of using to compromise up to 18,000 SolarWinds customers, including sensitive federal agencies, by hijacking the company's Orion network monitoring software.

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

Security researchers have previously said a second group of hackers was abusing SolarWinds' software at the same time as the alleged Russian hack, but the suspected connection to China and ensuing US government breach have not been previously reported.

Reuters was not able to establish how many organizations were compromised by the suspected Chinese operation. The sources, who spoke on condition of anonymity to discuss ongoing investigations, said the attackers used computer infrastructure and hacking tools previously deployed by state-backed Chinese cyberspies.

A USDA spokesman said in an email "USDA has notified all customers (including individuals and organizations) whose data has been affected by the SolarWinds Orion Code Compromise."

In a follow-up statement after the story was published, a different USDA spokesman said the NFC was not hacked and that "there was no data breach related to Solar Winds" at the agency. He did not provide further explanation.

The Chinese foreign ministry said attributing cyberattacks was a "complex technical issue" and any allegations should be supported with evidence. "China resolutely opposes and combats any form of cyberattacks and cyber theft," it said in a statement.

SolarWinds said it was aware of a single customer that was compromised by the second set of hackers but that it had "not found anything conclusive" to show who was responsible. The company added that the attackers did not gain access to its own internal systems and that it had released an update to fix the bug in December.

In the case of the sole client it knew about, SolarWinds said the hackers only abused its software once inside the client's network. SolarWinds did not say how the hackers first got in, except to say it was "in a way that was unrelated to SolarWinds."

The FBI declined to comment.

Although the two espionage efforts overlap and both targeted the US government, they were separate and distinctly different operations, according to four people who have investigated the attacks and outside experts who reviewed the code used by both sets of hackers.

While the alleged Russian hackers penetrated deep into SolarWinds network and hid a "back door" in Orion software updates which were then sent to customers, the suspected Chinese group exploited a separate bug in Orion's code to help spread across networks they had already compromised, the sources said.

'Extremely Serious Breach'

The side-by-side missions show how hackers are focusing on weaknesses in obscure but essential software products that are widely used by major corporations and government agencies.

"Apparently SolarWinds was a high value target for more than one group," said Jen Miller-Osborn, the deputy director of threat intelligence at Palo Alto Networks' Unit42.

Former US chief information security officer Gregory Touhill said separate groups of hackers targeting the same software product was not unusual. "It wouldn't be the first time we've seen a nation-state actor surfing in behind someone else, it's like 'drafting' in NASCAR," he said, where one racing car gets an advantage by closely following another's lead.

The connection between the second set of attacks on SolarWinds customers and suspected Chinese hackers was only discovered in recent weeks, according to security analysts investigating alongside the US government.

Reuters could not determine what information the attackers were able to steal from the National Finance Center (NFC) or how deep they burrowed into its systems. But the potential impact could be "massive," former US government officials told Reuters.

The NFC is responsible for handling the payroll of multiple government agencies, including several involved in national security, such as the FBI, State Department, Homeland Security Department and Treasury Department, the former officials said.

Records held by the NFC include federal employee social security numbers, phone numbers and personal email addresses as well as banking information. On its website, the NFC says it "services more than 160 diverse agencies, providing payroll services to more than 600,000 Federal employees."

"Depending on what data were compromised, this could be an extremely serious breach of security," said Tom Warrick, a former senior official at the U.S Department of Homeland Security. "It could allow adversaries to know more about US officials, improving their ability to collect intelligence."

Top News

suspected / Chinese Hackers / SolarWinds / bug / Spy / US payroll agency

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Deep depression over Bay of Bengal on 29 May. Photo: ANI
    Heavy rain, tidal surges trigger flood warnings as deep depression crosses coast
  • Powerful tidal surges from the Meghna River flooded more than 100 villages in four coastal upazilas of Lakshmipur on 29 May 2025. Photo: TBS
    Meghna tidal surge floods over 100 villages as incessant daylong rain batters Lakshmipur
  • Attackers vandalise the windows of the residence of Jatiyo Party (JaPa) Chairman GM Quader and set fire to a motorcycle in Rangpur on 29 May 2025. Photo: TBS
    Jatiyo Party chief GM Quader's Rangpur house attacked; NCP, SAD activists blamed

MOST VIEWED

  • Photo: Courtesy
    New notes featuring historic, archaeological structures of Bangladesh to be circulated from 1 June
  • Two Memoranda of Understanding were signed at the seminar titled “Bangladesh Seminar on Human Resources,” in Tokyo on 29 May 2025. Photo: CA Press Wing
    Japan to recruit 100,000 Bangladeshi workers over next 5 years
  • Representational Photo: Collected
    Country's all jewellery shops to remain indefinitely closed in protest of VP Reponul's arrest: Bajus
  • BAT Bangladesh has to vacate Mohakhali HQ as SC rejects lease appeal
    BAT Bangladesh has to vacate Mohakhali HQ as SC rejects lease appeal
  • Illustration: TBS
    Bangladesh repays $3.5b foreign debt in 10 months of FY25
  • Khondoker Rashed Maqsood. File Photo: Collected
    Investors urge removal of BSEC chairman in meeting with CA’s special assistant, submit list of demands

Related News

  • Mob beating kills 2 in Ctg: What's been revealed
  • As China hacking threat builds, Biden to order tougher cybersecurity standards
  • Chinese cyberattacks on Taiwan government averaged 2.4 mln a day in 2024: report
  • Chinese hack of US Treasury breached sanctions office: Washington Post
  • US Treasury says Chinese hackers stole documents in 'major incident'

Features

For hundreds of small fishermen living near this delicate area, sustainable fishing is a necessity for their survival. Photo: Syed Zakir Hossain

World Ocean Day: Bangladesh’s ‘Silent Island’ provides a fisheries model for the future

12h | The Big Picture
The university will be OK. But will the US? Photo: Bloomberg

A weaker Harvard is a weaker America

12h | Panorama
The Botanical Garden is a refuge for plant species, both native and exotic. Photo: Mehedi Hasan/TBS

The hidden cost of 'development' in the Botanical Garden

12h | Panorama
Stillbirths in Bangladesh: A preventable public health emergency

Stillbirths in Bangladesh: A preventable public health emergency

12h | Panorama

More Videos from TBS

Record migrant deaths in 2024

Record migrant deaths in 2024

9h | Podcast
News of The Day, 29 MAY 2025

News of The Day, 29 MAY 2025

11h | TBS News of the day
Businesses set for relief as interim govt eyes major tax & fine cuts

Businesses set for relief as interim govt eyes major tax & fine cuts

14h | TBS Insight
Love is essential for human life

Love is essential for human life

13h | TBS Programs
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net