Military & Defense

US intelligence agencies have issued a rare public statement saying that the SolarWinds hack was 'likely Russian in nature'

SolarWinds
SolarWinds banner at the New York Stock Exchange. REUTERS/Brendan McDermid
Read in app

A joint task force of investigative US government agencies issued a statement Tuesday saying that the massive SolarWinds hack was "likely Russian in nature."

The statement, which was also signed by the FBI, the Cybersecurity and Infrastructure Security Agency, and the National Security Agency, marked a rare unified public response to the hack.

The statement, which noted that investigations into the hack were still underway, said "an Advanced Persistent Threat (APT) actor, likely Russian in origin, is responsible for most or all of the recently discovered, ongoing cyber compromises of both government and non-governmental networks."

The statement added that the hack was likely "an intelligence-gathering effort." 

Tuesday's joint statement marked the first cohesive response from the intelligence community since the hack was identified, and it contradicted Trump's claims last month that Chinese hackers were responsible.  

The statement said the hack was "a serious compromise that will require a sustained and dedicated effort to remediate," adding that private-sector and US government employees have worked to contain the hack since discovering it.

The joint task force also offered additional clarity on which US agencies were targeted.

The statement said less than 10 federal bodies had networks breached, and those agencies included the Treasury, as well as the departments of State, Homeland Security, Commerce, and Energy.

Russian presidential spokesman Dmitry Peskov and the Russian Embassy in the US have denied that Russian hackers orchestrated the attacks. A statement issued on the embassy's Facebook page on December 13 said: "Malicious activities in the information space contradict the principles of the Russian foreign policy, national interests and our understanding of interstate relations."

It added: "Russia does not conduct offensive operations in the cyber domain."

The hack took place over the course of several months, likely beginning as early as March. Hackers entered the SolarWinds system — which monitors servers to prevent outages — via patch updates made by SolarWinds in March and June, the global cybersecurity firm FireEye said in a statement.

As hackers put corrupted code into SolarWinds updates, at least 18,000 SolarWinds customers in the public and private sectors installed tainted updates, according to US intelligence agencies.

The hack was publicly reported last month after FireEye detected the supply-chain attack, saying its own networks were also compromised.

Read next

Azmi Haroun is formerly Insider's Courts Reporter based in Los Angeles, California, working on Insider's News Team. He regularly covers high-profile celebrity court cases in Los Angeles, as well as legal and political affairs on a national and international level. In his time at Insider, he has profiled the legendary Nile Rodgers, scored court scoops on Vanessa Bryant and rapper Flo Rida, and kept an ear to the ground to cover landmark war crimes trials led by Syrians in Europe. He obtained a Master of Science from Columbia Journalism School in May 2020, and prior, worked in refugee resettlement during the fraught transition between the Obama and Trump administrations. He has lived in Morocco, France, and Dubai, during different stints and speaks French, Spanish, and Arabic.