It’s important to practice good cybersecurity when you’re at home or at your job. Don’t click links you can’t verify. Don’t open emails from people you don’t recognize trying to threaten or scare you. Don’t explore your well-read friend’s post littered with bad punctuation and grammar, their account is likely compromised.
It might scare you to know that you can have perfect digital hygiene and still be critically compromised by bad actors without your knowledge. This is true of anyone from a casual email user to the White House itself. How? The SolarWinds hack in 2019 is a frightening illumination of the digital vulnerability of our modern digital world.
The scope of the SolarWinds hack was massive. More than 18,000 entities were compromised, including nine U.S. agencies and numerous Fortune 500 companies. The White House itself was compromised by this hack, and the scariest part of all? The entities that were affected by this cyberattack weren’t even the ones responsible for it. No one in these companies opened a fishy email, no one gave away information to a scammer over the phone. Instead, the exploit was from a piece of support software used by all of these organizations, produced by a company in Texas called SolarWinds.
Software is a lot like any other manufactured good. Let’s compare a piece of software that manages scheduling to a hamburger. This piece of software is made up of a lot of little components — software is very rarely coded up from scratch by a single individual or entity. It’s built on preexisting programming that has to link up with other programs created by other businesses. It’s how the world runs. After all, your hamburger isn’t just a patty, it’s beef and lettuce and tomatoes and wheat and cheese that were all grown by different people to build one product.
Occasionally, there may be a listeria outbreak in lettuce, which could compromise your burger and give you a really bad weekend. Essentially, this is exactly what happened with the SolarWinds hack; but, instead of listeria, it was a Russian hacking group using a preexisting exploit with the intention of hiding in this obscure program until it flowed downstream in the supply chain to affect much bigger entities than a software company in Texas.
This is called a supply chain hack, and it is exceedingly common and scary for consumers. An obscure vendor or subcontractor serving a very large company that serves a vast number of consumers is compromised, and suddenly the entire network is at risk. You, as a consumer, are completely powerless to deal with the consequences.
Chances are, you don’t have the legal muscle to go after the company that indirectly infected you — it’s likely you aren’t even aware of how to find the vendor or subcontractor that’s actually at fault when your personal data is stolen. Such a level of powerlessness in this age is something we aren’t used to, but it’s something we’re all at risk of at every moment.
Let’s look at what happened. SolarWinds is a company that creates IT management software. Chances are, unless you’re an IT professional, you haven’t heard of them, as they sell exclusively to other companies to improve workflows for the IT field. Though you may not have heard of them, it’s very likely that the software they’ve built has peripherally touched your life in one way or another. Its tools were used by every U.S. telecommunications company, every branch of the U.S. military and the White House itself.
The actual nature of the attack isn’t precisely known. It’s presumed that hackers exploited a zero-day vulnerability (a loophole or exploit that is so new it hasn’t been patched yet), a brute force attack or a targeted phishing attack on SolarWinds engineers.
It was likely a mix of these tactics, with malicious software being injected through a link that appeared legitimate, exploiting a bug in Apple Safari that wouldn’t be patched for two years. Essentially, it existed to circumvent needing a user to manually log in every time they visited a webpage, but came with the added risk of also allowing malicious and harmful code to be downloaded when visiting the page. At this point, it takes information from the stored cookies, which includes critical login information for social media and internal systems. At that point, the hackers had a skeleton key for everything attached to SolarWinds’ software.
Here’s the scary part: Once the hackers had full access to SolarWinds’ systems, they did… nothing. At least not yet. They didn’t break systems worldwide with ransomware or wipers. Instead, they gained access to Orion, an important tool used by network engineers around the world, and implanted a Trojan into the software every time it updated. This gave them a backdoor into any system that used Orion.
Even scarier, the attackers disassembled a legitimate cybersecurity tool used by many of these entities, Cobalt Strike, and reengineered it to maintain access and mask their presence in affected devices. This was an extremely high-level operation, and one revealed to be perpetrated by the Russian Foreign Intelligence Service.
It is projected that hackers had access to the highest echelons of government for more than a year. These infiltrators had to custom-build tools to siphon data for each agency once they had access, which also meant they couldn’t just take all of the data in one massive download. They had to sneak bits and pieces out at a time, which may have worked to mitigate the damage of the attack.
Wondering how they were finally exposed? A cybersecurity engineer, Stephen Eckels, working for the company FireEye (now part of Trellix), noticed Cobalt Strike was being used on their system seemingly on its own. From there, they were able to trace injected code to a server extracting data, and expose the breach to customers affected by the exploit.
Stay curious, 7B.
Want to support independent local journalism?
The Sandpoint Reader is our town's local, independent weekly newspaper. "Independent" means that the Reader is locally owned and operated by people who were born and raised in Sandpoint. The Reader is owned by Publisher Ben Olson, Editor-in-Chief Zach Hagadone and Senior Writer Soncirey Mitchell. Sandpoint Reader LLC is a completely independent business unit; no big newspaper group or corporate conglomerate or billionaire owner dictates our editorial policy. And we want the news, opinion and lifestyle stories we report to be freely available to all interested readers - so unlike many other newspapers and media websites, we have NO PAYWALL on our website. The Reader relies wholly on the support of our valued advertisers, as well as readers who voluntarily contribute. Want to ensure that local, independent journalism survives in our town? You can help support the Reader for as little as $1.
TIMBER WARS: Six-part series, February-November 2022. GO READ IT»
WHERE ARE THE WORKERS?: Five-part series, September-October 2021. GO READ IT»
THE AMERICAN REDOUBT: Seven-part series, November-December 2017. GO READ IT»
STANDOFF AT RUBY RIDGE: 25 Years Later. Five-part series, August-September 2017. GO READ IT»
Curious about what media the locals use? Check our 2018 Local Media Survey. GO SEE »
Sandpoint in Pictures
Filmmaker Jimmy Matlosz of the Idaho Film Company has made a series of mini documentaries about influential Sandpoint locals, including the late Dann Hall and Erik Daarstad as well as icons Diane Michaels and Dan Shook. He is currently working on a series of interviews connected to the history of the Panida Theater. Jimmy is a 30-year veteran filmmaker who's work can be seen at dpmatlosz.com.
Meet the Reader
Ever wonder who makes the Reader happen? Here's a behind-the-scenes look pieced together by summer 2017 intern McCalee Cain in which Ben, Cameron and Lyndsie explain what exactly about the Reader keeps them coming back to their shabby (but well-loved) office each week.