CASE DOSSIER alleged

SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)

Docket: SEC CIK 0001739942 Court: U.S. District Court for the Southern District of New York Opened: 2020-12-13 Sector: Information Technology, Defense, Federal Government, Telecommunications

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$200.0 million
Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.
Techniques
5
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the Southern District of New York.
  • Primary Target Sector: Information Technology, Defense, Federal Government, Telecommunications.
  • Documented Financial Loss: $200.0 million.
  • 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.

Procedural & Incident Timeline

2020-12-14 disclosure

SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise.

2020-12-17 advisory

CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies.

2021-04-15 sanction

White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates." CISA Advisory AA20-352A ¶ 8 reviewed
T1071.001 Web Protocols
Command and Control
"The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols." CISA Advisory AA20-352A ¶ 14 reviewed
T1078 Valid Accounts
Defense Evasion
"Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments." CISA Emergency Directive 21-01 reviewed
T1132 Data Encoding
Command and Control
"SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters." CISA Advisory AA20-352A ¶ 16 reviewed
T1036 Masquerading
Defense Evasion
"The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence." CISA Advisory AA20-352A ¶ 21 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, SolarWinds Orion Supply Chain Intrusion (APT29 / SVR), No. SEC CIK 0001739942 (U.S. District Court for the Southern District of New York 2020), https://cyberattackcaselibrary.pages.dev/cases/solarwinds-orion-supply-chain-compromise/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/solarwinds-orion-supply-chain-compromise" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>