SOLARWINDS

The monitoring company whose own build system went unmonitored — and shipped a foreign intelligence service to eighteen thousand customers, digitally signed.

OPERATION
Network monitoring — the Orion platform, the "single pane of glass" into enterprise and government networks
HABITAT
Hundreds of thousands of customers, including much of the Fortune 500 and the U.S. federal government
EVENT
BUILD PIPELINE COMPROMISED — the SUNBURST backdoor compiled into signed Orion updates, 2020; up to ~18,000 customers downloaded it FACT
ATTRIBUTION
Russia's SVR (APT29), per the U.S. government's formal April 2021 attribution FACT
PATTERN
"solarwinds123" — a file-server password sitting in a public GitHub repo, attributed by the company's own former CEO to an intern ATTRIBUTED
DISPOSITION
SEC fraud charges (2023) → most claims dismissed July 2024 → the SEC abandoned the rest with prejudice, November 2025 ADJUDICATED

Here is the watcher of networks — the animal whose product is knowing what is running where — observed not knowing, for months, what was running inside its own build servers. The thing it shipped to fix visibility became the blind spot of an entire government.

Official channel: x.com/@solarwinds — the company's X account. FIRST-PARTY

"The SEC's lawsuit is fundamentally flawed — legally and factually — and we plan to defend vigorously against the charges… The SEC misleadingly quotes snippets of documents and conversations out of context to patch together a false narrative about our security posture." — SolarWinds, "Setting the Record Straight on the SEC and SUNBURST," company blog. The court later agreed with much of this; the SEC eventually walked away from all of it.

SUNBURST is the reference specimen of the supply-chain compromise: don't attack ten thousand networks, attack the one vendor all ten thousand trust to push signed code. The tradecraft was the SVR's. The unlocked workshop was SolarWinds'.

What makes this file worth keeping is the second act. The regulator tried to convert the breach into a fraud case against the company and its CISO — and lost, comprehensively, on the law and then by abandonment. Both halves are the record: the breach was real, and the fraud theory died in court. Every claim carries its receipt; the defense gets equal time.

the drama timeline

ACT I — THE IMPLANT (2019–2020)

The intruder does not smash a window. It gets a job in the factory and works, patiently, on the assembly line.

  1. SEP 2019 – FEB 2020

    Inside the build environment

    Per the reconstructed timeline, the threat actor first accesses SolarWinds' environment in September 2019, runs a test injection into Orion builds that October, and by February 2020 is compiling SUNBURST — a stealthy backdoor that waits about two weeks after install, then impersonates ordinary Orion telemetry traffic — into production code.

  2. MAR–JUN 2020

    18,000 signed deliveries

    Trojanized Orion updates — carrying SolarWinds' valid digital signature — go out to as many as 18,000 customers. The attackers then hand-pick a far smaller set for follow-on intrusion: federal agencies, Microsoft, FireEye, and other high-value networks.

    The signature is the whole trick. Every control the victims had — code signing, vendor trust, update hygiene — told them to install it.

ACT II — DETECTION, BY A VICTIM (DEC 2020)

As in the other files in this drawer, the vendor does not find the intruder. A customer does.

  1. DEC 8–13, 2020

    FireEye pulls the thread

    Security firm FireEye, investigating the theft of its own red-team tools, traces its intrusion back to the Orion supply chain and goes public. On December 13, CISA issues Emergency Directive 21-01, ordering all federal civilian agencies to disconnect or power down SolarWinds Orion products — immediately, and report back by noon the next day.

    Note the direction of discovery: the monitoring vendor was informed of its own compromise by a customer's incident response. The gatekeeper file two drawers over has the same note in the margin.

ACT III — THE PASSWORD AND THE ATTRIBUTION (2021)

Congress convenes, and the breach acquires its folk emblem: eleven lowercase characters and three digits.

  1. FEB 26, 2021

    "A mistake that an intern made"

    At a joint House hearing, current and former CEOs face the password "solarwinds123" — which researcher Vinoth Kumar had found in a public GitHub repository in 2019, where it had reportedly sat since 2018, protecting a SolarWinds file server. Former CEO Kevin Thompson's explanation under oath: "a mistake that an intern made… They violated our password policies." Rep. Katie Porter: "I've got a stronger password than 'solarwinds123' to stop my kids from watching too much YouTube on their iPad."

  2. APR 15, 2021

    The U.S. government names the SVR

    The White House and Treasury formally attribute the campaign to the Russian Foreign Intelligence Service (SVR), a.k.a. APT29 / Cozy Bear, and sanction Russian entities in response. The attribution converts the vendor's disaster into a named act of foreign espionage — a fact that cuts in both directions on this sheet.

ACT IV — THE REGULATOR AND THE REVERSAL (2023–2025)

The SEC attempts something new: charging the breached company, and its CISO personally, with fraud. Watch the theory shrink at every docket entry.

  1. OCT 30, 2023

    SEC v. SolarWinds and Brown

    The SEC charges SolarWinds and CISO Timothy G. Brown with fraud and internal control failures, alleging the company's public Security Statement misrepresented its practices while internal communications flagged known gaps. SolarWinds calls the case "fundamentally flawed — legally and factually." The infosec industry splits: precedent-setting accountability, or the criminalization of being breached?

  2. JUL 18, 2024

    Most of the case dies

    Judge Paul A. Engelmayer (S.D.N.Y.) issues a 107-page opinion dismissing most of the SEC's claims: the challenged press releases, blog posts, and podcasts were "non-actionable corporate puffery"; the post-incident disclosure claims relied on "the benefit of hindsight"; and the SEC's novel theory that internal accounting controls cover cybersecurity was rejected outright. Claims tied to the pre-breach Security Statement survive — for the moment.

  3. NOV 20, 2025

    The SEC walks away — with prejudice

    After the SEC conceded in a Joint Statement of Undisputed Facts that SolarWinds did implement practices described in its Security Statement — NIST Cybersecurity Framework use, role-based access, password complexity enforcement, secure development lifecycle measures — the parties stipulate to dismissal of all remaining claims against SolarWinds and Brown, with prejudice, with no settlement conditions. The landmark CISO-liability case ends with the regulator holding nothing.

    A dismissal with prejudice is as close as civil procedure comes to the word "never mind." It is on this sheet at the same size as the charges were.

both sides, on the record

The factory shipped the compromise. The backdoor was built inside SolarWinds' own pipeline and delivered under its own signature to ~18,000 customers, including the U.S. government [1] [3].

The hygiene emblem was real. "solarwinds123" sat exposed in public for over a year and was reported to the company by an outside researcher; leadership's explanation was an intern [8].

The vendor didn't detect it. A customer's incident response found SUNBURST; CISA had to order the government off the product by emergency directive [1] [9].

The adversary was a foreign intelligence service. The U.S. government itself attributed the operation to Russia's SVR — tradecraft that Mandiant called among the most evasive it had seen, and that also went undetected inside multiple federal agencies for months [2] [3].

The fraud theory failed on the merits it reached. The court found the challenged statements puffery or hindsight; the SEC then conceded key security practices were real and dismissed everything with prejudice. No fraud by SolarWinds or Brown was ever established — the opposite of an adverse judgment [5] [6] [7].

The password's role is disputed. The company maintained the leaked file-server credential was unrelated to the SUNBURST intrusion vector, and no public finding ties the two. The intern framing was the CEO's own testimony, not a court's [8].

YOU DECIDE

Scoped to the claims. The breach, its scope, and the SVR attribution are on the record. The password is on the record — and so is who leadership blamed for it. The fraud allegation was tested and did not survive: mostly dismissed on the law in 2024, abandoned with prejudice in 2025. Whether "the SVR did it" excuses the state of the workshop is the part you get to weigh.

The archive does not judge. It keeps the build logs.

evidence locker

PRIMARY & GOVERNMENT RECORD

  1. CISA — Emergency Directive 21-01, "Mitigate SolarWinds Orion Code Compromise" (Dec 13, 2020) FACT — the federal disconnect order. cisa.gov/news-events/directives/ed-21-01-mitigate-solarwinds-orion-code-compromise
  2. U.S. Treasury — sanctions announcement formally attributing the SolarWinds campaign to the SVR (Apr 15, 2021) FACT home.treasury.gov/news/press-releases/jy0127
  3. Mandiant (FireEye) — "Evasive Attacker Leverages SolarWinds Supply Chain Compromises With SUNBURST Backdoor" (Dec 2020) FACT — the detecting firm's technical analysis. cloud.google.com/blog/topics/threat-intelligence/…sunburst-backdoor/
  4. SEC — Press Release 2023-227, "SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures" (Oct 30, 2023) FACT-OF-CHARGE — allegations, as the SEC's. sec.gov/news/press-release/2023-227
  5. SEC v. SolarWinds Corp., S.D.N.Y. (CourtListener docket) ADJUDICATED — the filing, the July 2024 opinion, and the November 2025 stipulation of dismissal, on the public docket. courtlistener.com/docket/67927585/…

PRESS & ANALYSIS

  1. Harvard Law School Forum on Corporate Governance — "Court Dismisses Most of SEC's Claims Against SolarWinds" (Aug 2024) ATTRIBUTED corpgov.law.harvard.edu/2024/08/03/court-dismisses-most-of-secs-claims-against-solarwinds/
  2. Harvard Law School Forum on Corporate Governance — "SolarWinds Dismissed: What the SEC's U-turn Signals for Cyber Enforcement" (Dec 2025) ATTRIBUTED — the with-prejudice ending and the SEC's factual concessions. corpgov.law.harvard.edu/2025/12/07/solarwinds-dismissed-…
  3. CNN — "SolarWinds' former and current CEOs blame company intern for 'solarwinds123' password leak" (Feb 26, 2021) ATTRIBUTED — the hearing, the testimony, the researcher's discovery. cnn.com/2021/02/26/politics/solarwinds123-password-intern
  4. NPR — "A 'Worst Nightmare' Cyberattack: The Untold Story of the SolarWinds Hack" (Apr 2021) ATTRIBUTED — the long reconstruction, including the ~18,000 figure and the detection story. npr.org/2021/04/16/985439655/…
  5. TechTarget — "Judge tosses most of SEC's lawsuit against SolarWinds" (Jul 2024) ATTRIBUTED techtarget.com/searchsecurity/news/366596039/…

SUBJECT'S OWN CHANNELS

  1. SolarWinds — "Setting the Record Straight on the SEC and SUNBURST" (company blog) SELF-PUBLISHED — the defense, in the company's own words. solarwinds.com/blog/setting-the-record-straight-on-the-sec-and-sunburst
  2. X — @solarwinds (official account) FIRST-PARTY — account-level link only; no fabricated permalinks. x.com/solarwinds
The standard. The breach, its scope, and the attribution are sourced to CISA, Treasury, and the detecting firm. The password episode is sourced to the researcher who found it and the executives' own sworn testimony. The SEC's allegations are stated as allegations, and their fate — mostly dismissed on the law, then dismissed entirely with prejudice at the SEC's own agreement — is stated wherever the charges are, at the same volume. This is a failure file, not a fraud file: no court found fraud, and this page never says otherwise. If it couldn't survive a defamation challenge, it wouldn't be on this page.