Saudi Press

Saudi Arabia and the world
Thursday, Dec 04, 2025

What We Think Know About suspected Russia's Latest Alleged Hack Of The U.S. Government

What We Think Know About suspected Russia's Latest Alleged Hack Of The U.S. Government

The list of affected agencies is growing by the day. The full extent of the damage is still not clear, and U.S. authorities have provided few details.
Russian government hackers are believed to be responsible for infiltrating computer systems at multiple U.S. agencies in recent months, including the Pentagon, the Department of Homeland Security and the Department of the Treasury, according to government agencies and media reports. Russia has denied the accusations.

The hack hinged on a vulnerability on a software monitoring product from SolarWinds, a company based in Austin, Texas. The company works widely with the federal government and hundreds of large U.S. companies. Many use SolarWinds' Orion software to monitor their computer networks.

SolarWinds has some 300,000 customers, but says "fewer than 18,000" installed the version of its Orion products earlier this year that now appear to have been compromised.

So far, the list of affected U.S. government entities includes: The Commerce Department; Department of Homeland Security; the Pentagon; the Treasury Department; the U.S. Postal Service; and the National Institutes of Health.

The incident is the latest in what has become a long list of suspected Russian electronic incursions into other nations – particularly the U.S. – under President Vladimir Putin. Multiple countries say Russia was previously found to have used hackers, bots and other means in attempts to influence elections in the U.S. and elsewhere.

Many U.S. national security agencies made major efforts to prevent Russia from interfering in this year's election. But those same agencies seem to have been blindsided by news that hackers — suspected to be Russia's foreign intelligence service, the SVR — were digging around inside U.S. government systems, possibly since the spring.

"It's as if you wake up one morning and suddenly realize that a burglar has been going in and out of your house for the last six months," said Glenn Gerstall, who was the National Security Agency's general counsel from 2015 to 2020.

Describing some of the detective work that's now taking place, he added, "You'd have to go back and look at every room to see what was taken, what might have been touched. And of course, that's just a horrifying thought."

The intruders were very careful to cover their tracks, Gerstall said.

"You couldn't tell that they came in, you couldn't tell that they left the back door open. You couldn't even tell necessarily when they came in, took a look around and when they left."

To carry out the attack, hackers exploited the supply chain that SolarWinds uses to distribute software updates. The company says it has proof that when it sent updates to customers between March and June 2020, the updates to the Orion products also included malware that gave hackers access.

Microsoft has now taken control of the domain name that hackers used to communicate with systems that were compromised by the Orion update, according to security expert Brian Krebs. The company's analysis, he adds, should help reveal the scope of the affected companies and agencies.

So far, some U.S. government departments and agencies have acknowledged they are investigating the breaches, but have provided few details. The White House has been silent about the suspected Russian hack.

"This SolarWinds hack is very problematic, very troublesome, because it's not at all clear exactly how we should respond," Gerstall said. Part of the problem, he added, is that it's not clear what the hackers did after gaining access.

"This is not a question of someone manipulating software to open dams or turn off electric grids," Gerstall said. "It's not even clear that this is necessarily an attack designed to steal intellectual property the way China, for example, has stolen everything from patents for solar panels to the blueprints for fighter jets."

The intrusion could simply be a case of espionage, he said, of one government trying to understand what their adversary is doing.

Here's what key players are saying about the case:

SolarWinds: The company says, "We have been advised that this incident was likely the result of a highly sophisticated, targeted, and manual supply chain attack by an outside nation state, but we have not independently verified the identity of the attacker."

In an SEC filing, the company says it is cooperating with the FBI, the U.S. intelligence community and other agencies to investigate the breach.

SolarWinds says it was alerted to an "attack vector" that targeted its emails and other office productivity tools. The company adds that it uses Microsoft Office 365 for its office tools.

SolarWinds says it's working with Microsoft to determine if any customer data was exfiltrated, but it adds that so far, they have not found signs of stolen data.

The company says customers affected by the vulnerability should upgrade to the latest versions of its software "as soon as possible to ensure the security of your environment."

FireEye: The cybersecurity firm announced last week that a "highly sophisticated state-sponsored adversary" stole its "red team" tools, which are used to test security vulnerabilities in its customers' computer networks. FireEye's clients include government agencies.

The company says it's working with the FBI, Microsoft, and SolarWinds. And in an update issued late Sunday, FireEye said it has identified signs of compromised security in "multiple organizations," dating back to the spring of 2020. It also confirms others' findings of a sophisticated and meticulous attack.

"Our analysis indicates that these compromises are not self-propagating; each of the attacks require meticulous planning and manual interaction," FireEye said.

Microsoft: "We believe this is nation-state activity at significant scale, aimed at both the government and private sector," the company said, as it shared some details about what it calls "the threat activity we've uncovered over the past weeks."

Microsoft says the malicious code in the SolarWinds update gave hackers a foothold in the target's computer network, "which the attacker can use to gain elevated credentials." It adds that its Microsoft Defender software can now detect the files used in the hack.

The company applauded other firms for being open and transparent in revealing the hacking attacks, saying it will help others boost their security. As for Microsoft itself, the company said that so far, it hasn't "found evidence of a successful attack" in its own systems.

Cybersecurity and Infrastructure Security Agency: CISA said on Sunday that it "is aware of active exploitation of SolarWinds Orion Platform software" that was released between March 2020 and June 2020. The agency is urging any affected organizations to take steps to detect intrusions, and take countermeasures.
Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
As Trump Deepens Ties with Saudi Arabia, Push for Israel Normalization Takes a Back Seat
Thai Food Village Debuts at Saudi Feast Food Festival 2025 Under Thai Commerce Minister Suphajee’s Lead
Saudi Arabia Sharpens Its Strategic Vision as Economic Transformation Enters New Phase
Saudi Arabia Projects $44 Billion Budget Shortfall in 2026 as Economy Rebalances
OPEC+ Unveils New Capacity-Based System to Anchor Future Oil Output Levels
Will Saudi Arabia End Up Bankrolling Israel’s Post-Ceasefire Order in Lebanon?
Saudi Arabia’s SAMAI Initiative Surpasses One-Million-Citizen Milestone in National AI Upskilling Drive
Saudi Arabia’s Specialty Coffee Market Set to Surge as Demand Soars and New Exhibition Drops in December
Saudi Arabia Moves to Open Two New Alcohol Stores for Foreigners Under Vision 2030 Reform
Saudi Arabia’s AI Ambitions Gain Momentum — but Water, Talent and Infrastructure Pose Major Hurdles
Tensions Surface in Trump-MBS Talks as Saudi Pushes Back on Israel Normalisation
Saudi Arabia Signals Major Maritime Crack-Down on Houthi Routes in Red Sea
Italy and Saudi Arabia Seal Over 20 Strategic Deals at Business Forum in Riyadh
COP30 Ends Without Fossil Fuel Phase-Out as US, Saudi Arabia and Russia Align in Obstruction Role
Saudi-Portuguese Economic Horizons Expand Through Strategic Business Council
DHL Commits $150 Million for Landmark Logistics Hub in Saudi Arabia
Saudi Aramco Weighs Disposals Amid $10 Billion-Plus Asset Sales Discussion
Trump Hosts Saudi Crown Prince for Major Defence and Investment Agreements
Families Accuse OpenAI of Enabling ‘AI-Driven Delusions’ After Multiple Suicides
Riyadh Metro Records Over One Hundred Million Journeys as Saudi Capital Accelerates Transit Era
Trump’s Grand Saudi Welcome Highlights U.S.–Riyadh Pivot as Israel Watches Warily
U.S. Set to Sell F-35 Jets to Saudi Arabia in Major Strategic Shift
Saudi Arabia Doubles Down on U.S. Partnership in Strategic Move
Saudi Arabia Charts Tech and Nuclear Leap Under Crown Prince’s U.S. Visit
Trump Elevates Saudi Arabia to Major Non-NATO Ally Amid Defense Deal
Trump Elevates Saudi Arabia to Major Non-NATO Ally as MBS Visit Yields Deepened Ties
Iran Appeals to Saudi Arabia to Mediate Restart of U.S. Nuclear Talks
Musk, Barra and Ford Join Trump in Lavish White House Dinner for Saudi Crown Prince
Lawmaker Seeks Declassification of ‘Shocking’ 2019 Call Between Trump and Saudi Crown Prince
US and Saudi Arabia Forge Strategic Defence Pact Featuring F-35 Sale and $1 Trillion Investment Pledge
Saudi Sovereign Wealth Fund Emerges as Key Contender in Warner Bros. Discovery Sale
Trump Secures Sweeping U.S.–Saudi Agreements on Jets, Technology and Massive Investment
Detroit CEOs Join White House Dinner as U.S.–Saudi Auto Deal Accelerates
Netanyahu Secures U.S. Assurance That Israel’s Qualitative Military Edge Will Remain Despite Saudi F-35 Deal
Ronaldo Joins Trump and Saudi Crown Prince’s Gala Amid U.S.–Gulf Tech and Investment Surge
U.S.–Saudi Investment Forum Sees U.S. Corporate Titans and Saudi Royalty Forge Billion-Dollar Ties
Elon Musk’s xAI to Deploy 500-Megawatt Saudi Data Centre with State-backed Partner HUMAIN
U.S. Clears Export of Advanced AI Chips to Saudi Arabia and UAE Amid Strategic Tech Partnership
xAI Selects Saudi Data-Centre as First Customer of Nvidia-Backed Humain Project
A Decade of Innovation Stagnation at Apple: The Cook Era Critique
President Trump Hosts Saudi Crown Prince Mohammed bin Salman in Washington Amid Strategic Deal Talks
Saudi Crown Prince to Press Trump for Direct U.S. Role in Ending Sudan War
Trump Hosts Saudi Crown Prince: Five Key Takeaways from the White House Meeting
Trump Firmly Defends Saudi Crown Prince Over Khashoggi Murder Amid Washington Visit
Trump Backs Saudi Crown Prince Over Khashoggi Killing Amid White House Visit
Trump Publicly Defends Saudi Crown Prince Over Khashoggi Killing During Washington Visit
President Donald Trump Hosts Saudi Crown Prince Mohammed bin Salman at White House to Seal Major Defence and Investment Deals
Saudi Arabia’s Solar Surge Signals Unlikely Shift in Global Oil Powerhouse
Saudi Crown Prince Receives Letter from Iranian President Ahead of U.S. Visit
Saudi Arabia’s Crown Prince Begins Washington Visit to Cement Long-Term U.S. Alliance
×