Orion hack exposed vast number of targets – impact may not be known for a while

If there is one silver lining to the months-long global cyber-espionage campaign discovered when a prominent cybersecurity firm learned it had been breached, it might be that the sheer numbers of potentially compromised entities offers them some protection.

By compromising one piece of security software – a security tool called Orion developed by the Texan company SolarWinds – the attackers gained access to an extraordinary array of potential targets in the US alone: more than 425 of the Fortune 500 list of top companies; all of the top 10 telecommunications companies; all five branches of the military; and all of the top five accounting firms.

But they are just a fraction of SolarWinds’ 300,000 global customers, which also include UK government agencies and private sector companies.

Share

Kremlin-backed hackers breach US Treasury and Commerce: Report

A “sophisticated hacking group” backed by the Russian government reportedly infiltrated the Department of Treasury’s systems and stole information related to internet and telecommunications policymaking as part of a broader campaign that also hacked the Commerce Department and other government agencies.

The FBI is investigating the attacks and is looking into the Russian hacking group APT29, also known as Cozy Bear, as a potential culprit, according to the Washington Post. The foreign-backed hack was first reported by Reuters.

As a result of the hack, the National Security Council held a meeting at the White House on Sunday.

Share