December 17, 2020

US Government joins other nations and organizations targeted in a series of global cyber attacks

The recently identified months-long hack into the SolarWinds® Orion® Platform software, which is responsible for monitoring the computer networks of tens of thousands of private users, including fortune-500 companies and worldwide government agencies, is considered to be one of the largest and more sophisticated attacks against US government agencies and officials in the past years.

In an announcement from December 16th, SolarWinds reported that the hack targeted versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 of its Orion software. By getting tens of thousands of private and government users to download an Orion software update that was contaminated with a malicious code, hackers gained remote access to servers on which Orion operated, and was able to steal sensitive information.

The breach was detected after top cybersecurity company FireEye announced a breach to its SolarWinds software. However, to date, it remains unclear which government agencies were compromised by the attack.

While specific attackers were not identified, it is assessed that the attack was carried out by Russian agents. SolarWinds is now reportedly working with FireEye as well as the FBI in investigating the breach, which, according to FireEye, presented remarkable cyber capabilities.

Few of the proposed mitigation steps to secure the Orion platform include:

The attack on the US government joins other identified cyber-attacks that have been carried out towards the end of 2020 and targeted different nations, including Israel. Recent significant cyber-attacks, targeting over 80 targets in the Israeli economy were carried out by Iranian hacker groups and other players. These attacks targeted both local private organizations, such as Insurance agencies, and government bodies, such as a local water reservoir.

TSOC’s IR team works around the clock to provide support and assistance to organizations. At this time, it is important to remember a few basic principles:

Follow Us on Facebook for the latest news and insights on cybersecurity. 

Stay Safe with TrustNet!