This website collects cookies to deliver better user experience. Cookie Policy
Accept
Sign In
The Wall Street Publication
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Reading: SolarWinds Hackers Step Up Attacks on Tech Companies
Share
The Wall Street PublicationThe Wall Street Publication
Font ResizerAa
Search
  • Home
  • Trending
  • U.S
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
    • Markets
    • Personal Finance
  • Tech
  • Lifestyle
    • Lifestyle
    • Style
    • Arts
  • Health
  • Sports
  • Entertainment
Have an existing account? Sign In
Follow US
© 2024 The Wall Street Publication. All Rights Reserved.
The Wall Street Publication > Blog > Business > SolarWinds Hackers Step Up Attacks on Tech Companies
Business

SolarWinds Hackers Step Up Attacks on Tech Companies

Editorial Board Published October 25, 2021
Share
SolarWinds Hackers Step Up Attacks on Tech Companies
SHARE

The Russia-linked hackers behind last year’s compromise of a wide swath of the U.S. government and scores of private companies, including SolarWinds Corp. SWI 0.43% , have stepped up their attacks in recent months, breaking into technology companies in an effort to steal sensitive information, cybersecurity experts said.

In a campaign that dates back to May of this year, the hackers have targeted more than 140 technology companies including those that manage or resell cloud-computing services, according to new research from Microsoft Corp. MSFT -0.51% The attack, which was successful with as many as 14 of these technology companies, involved unsophisticated techniques like phishing or simply guessing user passwords in hopes of gaining access to systems, Microsoft said.

“This recent activity is another indicator that Russia is trying to gain long-term, systematic access to a variety of points in the technology supply chain,” said Tom Burt, Microsoft’s corporate vice president for customer security and trust, according to a blog post provided ahead of the announcement by Microsoft on Monday.

Security experts say last year’s SolarWinds incident was concerning because it showed how a compromise at one widely used link in the technology supply chain could be made into a jumping off point for further attacks. After government officials attributed it to Russia’s foreign intelligence service, the Biden administration in April punished Moscow for the attack and other alleged malicious cyber activity with financial sanctions and diplomatic expulsions.

That doesn’t appear to have deterred the hackers. Microsoft says it observed the group linked to the SolarWinds attack targeting 609 companies 22,868 times between July 1 and Oct. 19 of this year. That is more attempts than Microsoft observed from all government-linked hackers in the previous three years, Mr. Burt said.

The intrusion at SolarWinds, which went undiscovered for more than a year, was part of a hacking campaign that gave intruders footholds in at least nine federal agencies and 100 private companies. Microsoft itself and the cybersecurity company FireEye were compromised during the incident.

But not all of the break-ins involved SolarWinds software. Government officials say 30% of the victims didn’t use SolarWinds products.

The hack is regarded as one of the U.S.’s worst intelligence failures in years. Moscow has denied involvement. A representative for the Russian embassy in Washington didn’t immediately respond to a message seeking comment.

Ransomware attacks are increasing in frequency, victim losses are skyrocketing, and hackers are shifting their targets. WSJ’s Dustin Volz explains why these attacks are on the rise and what the U.S. can do to fight them. Photo illustration: Laura Kammermann

The latest disclosure of Russia’s alleged activities comes as the Biden administration has sought to curtail Moscow’s cyber aggression through a variety of means, including ongoing bilateral meetings intended to address a glut of ransomware attacks from Russian cybercriminal gangs on critical American infrastructure and businesses. Officials have offered mixed views on whether Moscow has cracked down on those criminal groups in response to U.S. pressure.

A U.S. government official briefed on Microsoft’s findings said the latest intrusion attempts appeared to be largely routine hacking handiwork from Russia.

“Based on the details in Microsoft’s blog, the activities described were unsophisticated password spray and phishing, run-of-the mill operations for the purpose of surveillance that we already know are attempted every day by Russia and other foreign governments,” the U.S. government official said.

The official said the attempted intrusions “could have been prevented if the cloud service providers had implemented baseline cybersecurity practices, including multifactor authentication,” referring to account features that require verifying a login with a code sent to a phone or other device.

SolarWinds, a seller of network management software, remains unsure of how it was first breached, but company executives and investigators have said that the initial point of entry could have been the same type of unsophisticated techniques that Microsoft has observed in this more recent activity.

Supply chain cybersecurity has drawn unprecedented interest in Washington over the past several months, in part due to the devastating and wide-ranging impact of the SolarWinds compromise. Last week, the U.S. House of Representatives passed a bill 412-2 that would require the Department of Homeland Security to issue guidance to federal contractors asking them to submit details of software in their own supply chains—including origins of technology—to DHS for potential review.

The congressional action follows an executive order signed by President Biden in May, also shaped in part by the SolarWinds breach, that created baseline cybersecurity standards for U.S. agencies and their software contractors, including mandates to use multifactor authentication and data encryption.

“The SolarWinds incident was a turning point for our nation,” Gen. Paul Nakasone, the director of the National Security Agency and U.S. Cyber Command, said at a conference earlier this month, calling it a “significant intrusion by a foreign adversary that was trying to do our nation harm.”

Write to Robert McMillan at [email protected] and Dustin Volz at [email protected]

Copyright ©2021 Dow Jones & Company, Inc. All Rights Reserved. 87990cbe856818d5eddac44c7b1cdeb8

TAGGED:Business NewsPAIDWall Street Publication
Share This Article
Twitter Email Copy Link Print
Previous Article Tesla Supplier Shows Off More Powerful Battery Tesla Supplier Shows Off More Powerful Battery
Next Article 129-year journey nears end as France returns Benin treasures 129-year journey nears end as France returns Benin treasures

Editor's Pick

Denise Richards Granted Restraining Order, Accuses Ex of Abuse

Denise Richards Granted Restraining Order, Accuses Ex of Abuse

Studying Time: 4 minutes Earlier this month, Denise Richards and Aaron Phypers started what's already shaping as much as be…

By Editorial Board 5 Min Read
Mike Rowe reveals which important jobs AI cannot contact – and why Individuals ought to concentrate
Mike Rowe reveals which important jobs AI cannot contact – and why Individuals ought to concentrate

HireQuest Inc., President and CEO Rick Hermanns analyzes the state of America's…

4 Min Read
Main drugmakers provide massive low cost on blood thinner Eliquis
Main drugmakers provide massive low cost on blood thinner Eliquis

'The Large Cash Present' panel discusses President Donald Trump's plan to convey…

4 Min Read

Oponion

Facebook Parent Meta’s Shares Fall to New Multiyear Lows

Facebook Parent Meta’s Shares Fall to New Multiyear Lows

TechCompany posts second consecutive quarter of declining revenue and warns…

October 27, 2022

Stocks Drop After Inflation Report

Stocks dropped Thursday as bond yields…

February 10, 2022

Disney closing decades-old trip this summer time to revamp with new tech

Disney showcases new blasters, targets coming…

March 26, 2025

‘Sister Wives’: Will Christine Brown Ever Depart the Present?

Is Christine Brown prepared to go…

September 15, 2024

Firms, together with Krispy Kreme and UberEats, roll out offers for Election Day

'Particular Report' anchor Bret Baier discusses…

November 11, 2024

You Might Also Like

Thales Reinforces its Management in eSIM and IoT Connectivity with a ‘Ready to Use’ Licensed Resolution
Business

Thales Reinforces its Management in eSIM and IoT Connectivity with a ‘Ready to Use’ Licensed Resolution

At a time when billions of linked objects are reshaping industries, Thales has achieved a vital safety certification for its…

4 Min Read
Soracom IoT Platform Achieves SOC 2 Kind 2 Compliance for Safety, Availability, and Confidentiality
Business

Soracom IoT Platform Achieves SOC 2 Kind 2 Compliance for Safety, Availability, and Confidentiality

Soracom, Inc., right now introduced that it has efficiently achieved System and Group Controls (SOC) 2 Kind 2 compliance, reinforcing…

2 Min Read
Mobile IoT Module Shipments Grew 23% in Q1 2025 as US–China tensions affect vendor panorama
Business

Mobile IoT Module Shipments Grew 23% in Q1 2025 as US–China tensions affect vendor panorama

In brief Shipments of mobile IoT modules and chipsets grew 23% year-over-year in Q1 2025, based on IoT Analytics’ International…

20 Min Read
Prime 7 Visitor Posting Marketplaces to Purchase Visitor Posts That Drive Search engine optimization Outcomes
Business

Prime 7 Visitor Posting Marketplaces to Purchase Visitor Posts That Drive Search engine optimization Outcomes

Utilizing a visitor posting market helps you overlook all that like a nasty nightmare. However how do you discover probably…

14 Min Read
The Wall Street Publication

About Us

The Wall Street Publication, a distinguished part of the Enspirers News Group, stands as a beacon of excellence in journalism. Committed to delivering unfiltered global news, we pride ourselves on our trusted coverage of Politics, Business, Technology, and more.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • WP Creative Group
  • Accessibility Statement

Contact

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 The Wall Street Publication. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?