CASE DOSSIER
alleged
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
Docket: SEC CIK 0001739942 Court: U.S. District Court for the Southern District of New York Opened: 2020-12-13 Sector: Information Technology, Defense, Federal Government, Telecommunications
Key Facts
Status
ALLEGED
Legal disposition
Loss Amount
$200.0 million
Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.
Techniques
5
Verified mappings
Defendants
0
Named in charges
- Legal Status: ALLEGED in U.S. District Court for the Southern District of New York.
- Primary Target Sector: Information Technology, Defense, Federal Government, Telecommunications.
- Documented Financial Loss: $200.0 million.
- 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.
Procedural & Incident Timeline
2020-12-14 disclosure
SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise.
2020-12-17 advisory
CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies.
2021-04-15 sanction
White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates." | CISA Advisory AA20-352A ¶ 8 | reviewed |
| T1071.001 | Web Protocols Command and Control | "The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols." | CISA Advisory AA20-352A ¶ 14 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments." | CISA Emergency Directive 21-01 | reviewed |
| T1132 | Data Encoding Command and Control | "SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters." | CISA Advisory AA20-352A ¶ 16 | reviewed |
| T1036 | Masquerading Defense Evasion | "The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence." | CISA Advisory AA20-352A ¶ 21 | reviewed |
CISA Cybersecurity Advisories
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, SolarWinds Orion Supply Chain Intrusion (APT29 / SVR), No. SEC CIK 0001739942 (U.S. District Court for the Southern District of New York 2020), https://cyberattackcaselibrary.pages.dev/cases/solarwinds-orion-supply-chain-compromise/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/solarwinds-orion-supply-chain-compromise" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>