Vendor lineage
SolarWinds
Sold the software that watches everything, which is exactly why somebody wanted it.
SolarWinds was founded in 1999 in Tulsa, Oklahoma by two brothers, Donald Yonce - a former Walmart executive - and David Yonce. The business was unglamorous and very good: affordable network monitoring for the people who actually run networks, sold without the enterprise sales apparatus that made competitors expensive. It moved to Austin, and by 2020 its Orion platform sat inside a very large share of the organisations that matter.
The commercial insight was that monitoring was overpriced and oversold. A network engineer who needed to know whether a link was saturated did not want a six-month procurement cycle, and SolarWinds built a catalogue of tools that could be downloaded, trialled and bought on a card. That model took it from Tulsa to a public listing in October 2018, and it bought its way into adjacent categories along the way: Pingdom for external uptime checks, Papertrail for log aggregation, Loggly, AppOptics.
**And then the thing that makes this page worth reading.** In October 2019, attackers who had already been inside SolarWinds began testing whether they could inject code into the Orion build. Roughly four months later they succeeded, and from 26 March 2020 SolarWinds itself distributed the result - a backdoor the industry named SUNBURST - inside signed, legitimate updates to Orion versions 2019.4 through 2020.2.1.
It was not discovered until December 2020, and not by SolarWinds. FireEye found it while investigating its own compromise, which is worth noting because FireEye appears on this timeline too: a security company found the largest supply chain attack in history by looking into how it had itself been broken into. In April 2021 the US and UK governments attributed the operation to Russia's foreign intelligence service, the SVR - the group tracked as APT29 or Cozy Bear.
**The number everyone quotes needs its caveat.** Around 18,000 customers received the backdoored update. The US government's own assessment was that a much smaller number were actually compromised by follow-on activity, because the backdoor was a door rather than an occupation - the attackers chose where to walk through it, and they were extremely selective. Repeating 18,000 as a count of victims overstates it, and the distinction between having the malware and being exploited by it is precisely the distinction a security professional is paid to understand.
The response detail that stays with people: SolarWinds could not use its own email to coordinate the investigation, because the attackers were reading it. Staff worked by telephone and outside accounts, during a pandemic, from home. The chief executive later joked that every comma in the initial regulatory filing cost the company $20,000 in legal fees.
**Then the argument about blame, which is not settled and is presented here as unsettled.** In October 2023 the SEC charged SolarWinds and its chief information security officer, Timothy Brown, with fraud - alleging that from the 2018 listing onward the company disclosed only generic risks while internally knowing about specific deficiencies. SolarWinds called the action an attempt to "revictimise the victim" and said its disclosures were accurate. In July 2024 a federal judge **dismissed most of the case**, including everything relating to disclosures made after the attack, while allowing the claim based on the company's published security statement to proceed.
That outcome is the part with teeth for anyone who works in this field. A named individual was personally charged over how a breach was described, and while most of the case did not survive, the surviving part concerns a marketing page about security practices. What a company says about its own posture became a matter of securities law, and every CISO reading this now writes differently because of it.
The lesson for practitioners is architectural rather than moral, and this site already carries its twin. CrowdStrike's July 2024 outage broke 8.5 million machines because a trusted agent with deep access is updated centrally and rapidly. SUNBURST compromised thousands of networks for the same structural reason. **One was an accident and one was an intelligence operation, and the property they exploited was identical: we have built an industry on software that updates itself from a single source, and the trust in that channel is load-bearing.**
2014 Pingdom
External uptime and performance monitoring, checked from outside the network rather than within it.
The SolarWinds cloud monitoring line.
2015 Papertrail
Hosted log aggregation and live tail, popular with small engineering teams for being immediately useful.
Part of the same cloud portfolio, kept under its own name.
2015 Librato and TraceView
Metrics and application tracing, bought from AppNeta.
AppOptics, which merged both into one product.
- Wikipedia: SolarWinds - founded 1999 in Tulsa by Donald and David Yonce; Brad Smith's assessment of the attack
- MITRE ATT&CK campaign C0024 - the April 2021 US and UK attribution to Russia's SVR, and the government assessment that far fewer than the ~18,000 recipients were actually compromised
- Fortinet: the timeline - testing code injection in October 2019, SUNBURST injected about four months later, distribution beginning 26 March 2020
- SEC litigation release: the October 2023 charges against SolarWinds and CISO Timothy Brown, and the ~25% and ~35% share price falls after the 14 December 2020 filing
- Cybersecurity Dive: the July 2024 ruling dismissing most of the SEC case while sustaining the claim based on the security statement
- The Register: SolarWinds' own characterisation of the SEC action as revictimising the victim
- Zscaler: the affected Orion versions 2019.4 through 2020.2.1 and the breadth of US government customers