Hackers used SolarWinds' dominance against it in sprawling spy campaign | The Business Standard
Skip to main content
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Saturday
July 05, 2025

Sign In
Subscribe
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
SATURDAY, JULY 05, 2025
Hackers used SolarWinds' dominance against it in sprawling spy campaign

Tech

Reuters
16 December, 2020, 07:00 pm
Last modified: 16 December, 2020, 07:09 pm

Related News

  • Phishing trap: How a college student’s life was turned upside down
  • Reuters exposé of hack-for-hire world is back online after Indian court ruling
  • China are the real hackers not us, Taiwan says after cyber accusations
  • Dispossessor ransomware group shut down by US, European authorities
  • Microsoft says it caught hackers from China, Russia and Iran using its AI tools

Hackers used SolarWinds' dominance against it in sprawling spy campaign

Cybersecurity experts are still struggling to understand the scope of the damage

Reuters
16 December, 2020, 07:00 pm
Last modified: 16 December, 2020, 07:09 pm
Hackers used SolarWinds' dominance against it in sprawling spy campaign

On an earnings call two months ago, SolarWinds Chief Executive Kevin Thompson touted how far the company had gone during his 11 years at the helm.

There was not a database or an IT deployment model out there to which his Austin, Texas-based company did not provide some level of monitoring or management, he told analysts on the Oct. 27 call.

"We don't think anyone else in the market is really even close in terms of the breadth of coverage we have," he said. "We manage everyone's network gear."

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

Now that dominance has become a liability - an example of how the workhorse software that helps glue organizations together can turn toxic when it is subverted by sophisticated hackers.

On Monday, SolarWinds confirmed that Orion - its flagship network management software - had served as the unwitting conduit for a sprawling international cyberespionage operation. The hackers inserted malicious code into Orion software updates pushed out to nearly 18,000 customers.

And while the number of affected organizations is thought to be much more modest, the hackers have already parlayed their access into consequential breaches at the US Treasury and Department of Commerce.

Three people familiar with the investigation have told Reuters that Russia is a top suspect, although others familiar with the inquiry have said it is still too early to tell.

A SolarWinds representative, Ryan Toohey, said he would not be making executives available for comment. He did not provide on-the-record answers to questions sent via email.

In a statement issued Sunday, the company said "we strive to implement and maintain appropriate administrative, physical, and technical safeguards, security processes, procedures, and standards designed to protect our customers."

Cybersecurity experts are still struggling to understand the scope of the damage.

The malicious updates - sent between March and June, when America was hunkering down to weather the first wave of coronavirus infections - was "perfect timing for a perfect storm," said Kim Peretti, who co-chairs Atlanta-based law firm Alston & Bird's cybersecurity preparedness and response team.

Assessing the damage would be difficult, she said.

"We may not know the true impact for many months, if not more – if not ever," she said.

The impact on SolarWinds was more immediate. US officials ordered anyone running Orion to immediately disconnect it. The company's stock has tumbled more than 23% from $23.50 on Friday - before Reuters broke the news of the breach - to $18.06 on Tuesday.

SolarWinds' security, meanwhile, has come under new scrutiny.

In one previously unreported issue, multiple criminals have offered to sell access to SolarWinds' computers through underground forums, according to two researchers who separately had access to those forums.

One of those offering claimed access over the Exploit forum in 2017 was known as "fxmsp" and is wanted by the FBI "for involvement in several high-profile incidents," said Mark Arena, chief executive of cybercrime intelligence firm Intel471. Arena informed his company's clients, which include US law enforcement agencies.

Security researcher Vinoth Kumar told Reuters that, last year, he alerted the company that anyone could access SolarWinds' update server by using the password "solarwinds123"

"This could have been done by any attacker, easily," Kumar said.

Neither the password nor the stolen access is considered the most likely source of the current intrusion, researchers said.

Others - including Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress - noticed that, days after SolarWinds realized their software had been compromised, the malicious updates were still available for download.

The firm has long mooted the idea of spin-off of its managed service provider business and on Dec. 9 announced that Thompson would be replaced by Sudhakar Ramakrishna, the former chief executive of Pulse Secure. Three weeks ago, SolarWinds posted a job ad seeking a new vice president for security; the position is still listed as open.

Thompson and Ramakrishna could not be reached for comment.

World+Biz

Hackers / SolarWinds / spy campaign

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Graphics: TBS
    How courier failures are undermining Bangladesh’s online perishables trade
  • Students of different institutions protest demanding the reinstatement of the 2018 circular cancelling quotas in recruitment in government jobs. Photo: Mehedi Hasan
    5 July 2024: Students announce class boycott amid growing protests
  • Students staged a demonstration in front of the vice chancellor's office at CU on 4 July. Photo: Collected
    CU halts teacher’s promotion after protesters lock in VC, top officials

MOST VIEWED

  • 3 July 2024: Momentum builds as quota protest enters third day
    3 July 2024: Momentum builds as quota protest enters third day
  • What it will take to merge crisis-hit Islamic banks
    What it will take to merge crisis-hit Islamic banks
  • A meeting of the Advisory Council Committee chaired by the Chief Adviser Muhammad Yunus held on 3 July 2025. Photo: PID
    Govt Service Ordinance: Compulsory retirement to replace dismissal for misconduct in govt job 
  • NCC Bank’s operations to remain suspended for 120 hours from 8 July
    NCC Bank’s operations to remain suspended for 120 hours from 8 July
  • Graphics: TBS
    Foreign currency in offshore banking units now eligible as collateral for taka loans
  • Govt to pay 3-year high ACU bill of $2b next week
    Govt to pay 3-year high ACU bill of $2b next week

Related News

  • Phishing trap: How a college student’s life was turned upside down
  • Reuters exposé of hack-for-hire world is back online after Indian court ruling
  • China are the real hackers not us, Taiwan says after cyber accusations
  • Dispossessor ransomware group shut down by US, European authorities
  • Microsoft says it caught hackers from China, Russia and Iran using its AI tools

Features

Students of different institutions protest demanding the reinstatement of the 2018 circular cancelling quotas in recruitment in government jobs. Photo: Mehedi Hasan

5 July 2024: Students announce class boycott amid growing protests

3h | Panorama
Contrary to long-held assumptions, Gen Z isn’t politically clueless — they understand both local and global politics well. Photo: TBS

A misreading of Gen Z’s ‘political disconnect’ set the stage for Hasina’s ouster

7h | Panorama
Graphics: TBS

How courier failures are undermining Bangladesh’s online perishables trade

7h | Panorama
The July Uprising saw people from all walks of life find themselves redrawing their relationship with politics. Photo: Mehedi Hasan

Red July: The political awakening of our urban middle class

16h | Panorama

More Videos from TBS

Ukraine war: Trump under pressure from his own party

Ukraine war: Trump under pressure from his own party

8h | TBS World
News of The Day, 04 JULY 2025

News of The Day, 04 JULY 2025

7h | TBS News of the day
Contractor witnesses shooting of hungry people in Gaza

Contractor witnesses shooting of hungry people in Gaza

9h | TBS Stories
Russia first country to recognize Taliban rule

Russia first country to recognize Taliban rule

13h | TBS World
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net