• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Project of the Week
  • About Us
    SEARCH
IT Infrastructure, Mobility, Network Security, News

Microsoft Identifies 40+ Victims of SolarWinds Hack, Including IT Companies

Microsoft says it has identified more than 40 victims of the SolarWinds Orion supply chain compromise, including several more IT and software companies.

December 18, 2020 Zachary Comeau Leave a Comment

Microsoft January Patch Tuesday
wolterke/stock.adobe.com

According to Microsoft, it has identified more than 40 victims of the wide-ranging SolarWinds Orion supply chain compromise that were breached further by hackers believed to be backed by a foreign state-backed entity.

In a blog post, Microsoft said 44% of the 40-plus entities that were further breached by hackers in the large-scale attack are other IT companies, meaning hackers may have accessed and used additional private sector software  to further their attack.

While the companies weren’t named, Microsoft said they include software firms, IT services and equipment providers.

Meanwhile, government and think tanks each make up 18% of the victims, while government contractors make up 9% of the victims. Another 11% are uncategorized.

Microsoft’s role in response grows

The information came by way of the lengthy blog written by Microsoft President Brad Smith, who echoed the statements of FireEye CEO Kevin Mandia who earlier this week commented on the unprecedented sophistication of the attack:

“The attack unfortunately represents a broad and successful espionage-based assault on both the confidential information of the U.S. Government and the tech tools used by firms to protect them,” Smith wrote.

“The attack is ongoing and is being actively investigated and addressed by cybersecurity teams in the public and private sectors, including Microsoft. As our teams act as first responders to these attacks, these ongoing investigations reveal an attack that is remarkable for its scope, sophistication and impact.”

Smith’s blog came Thursday, and an editor’s note at the bottom that came just before 11 p.m. ET references news reports about Microsoft itself being a victim of the hack.

Reuters on Thursday, citing anonymous sources, said Microsoft has found indications that hackers were able to infiltrate the company’s networks and use Microsoft tools and IT dominance to further their attacks on other entities.

However, Microsoft threw cold water on that report, saying it did detect malicious SolarWinds binaries in the company’s environment, but company security experts isolated and removed them.

Microsoft claims it has not found evidence of access to production services or customer data, and there are no indications that Microsoft systems were used to attack others.

Smith laid out other important information in the blog, including where the attacks were focused. About 80% of victims are located in the U.S., but victims are also located in Canada, Mexico, Belgium, Spain, the U.K. and Israel.

“It’s certain that the number and location of victims will keep growing,” Smith wrote.

The company, along with other tech firms, has been actively fighting back, sinking a domain used as a command and control sever in the attacks and releasing tools that help detect, block and quarantine the malicious code. 

Oher IT companies likely to be involved

Statements by government officials back up Smith’s claim. The U.S. Cybersecurity and Infrastructure Agency on Thursday issued an alert that it “has evidence of additional initial access vectors” other than the SolarWinds Orion platform. These are still being investigated.

“The SolarWinds Orion supply chain compromise is not the only initial infection vector this APT actor leveraged,” the alert said.

Investigation has revealed that attackers accessed the networks of some victims without utilizing the vulnerability in the SolarWinds Orion platform. SolarWinds has said that there is no evidence of its other products being leveraged by attackers, meaning tools from other IT vendors are being used in these attacks.

According to SolarWinds, about 18,000 of its customers were susceptible to the attacks, but the attackers are mostly targeting government entities, organizations that do business with the government and others in the IT supply chain that could give them access to a wide range of other networks.

So far, investigators believe the attackers further accessed the networks and information of FireEye, The U.S. Commerce and Treasury departments and other important government agencies.

A list of SolarWinds’ high-profile customers includes dozens of well-known tech companies, hardware providers and defense contractors, but so far none have come forward and disclosed that they had been breached further.

Politico reported Thursday that the U.S. Energy Department and National Nuclear Security Administration — the agency that oversees the country’s nuclear weapons arsenal — was also a victim.

Cybersecurity vendor Volexity said earlier this week that before the attack in question, it observed a compromise of a U.S.-based think tank using a Duo multi-factor authentication bypass in Outlook Web App as an initial intrusion vector.

“Volexity attributes this intrusion to the same activity as the SolarWinds Orion supply chain compromise, and the TTPs are consistent between the two,” reads a Thursday alert from CISA. “This observation indicates that there are other initial access vectors beyond SolarWinds Orion, and there may still be others that are not yet known.”

If you enjoyed this article and want to receive more valuable industry content like this, click here to sign up for our digital newsletters!

Tagged With: Cybersecurity, Microsoft, SolarWinds

Related Content:

  • Cloud, SASE, Aryaka How the Cloud is Redefining Media Production and…
  • Singlewire Software mass notification interview Singlewire Software on Mass Notification Solutions
  • URI catchbox 1 Catchbox Plus: The Mic Solution That Finally Gave…
  • Engaging virtual meeting with diverse participants discussing creative ideas in a bright office space during daylight hours Diversified Survey: Workplace AV Tech is Falling Short,…

Free downloadable guide you may like:

  • Practical Design Guide for Office SpacesPractical Design Guide for Office Spaces

    Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-face time with co-workers. When designing the office spaces — and meeting spaces in particular — enabling that connection between co-workers is crucial. But introducing the right collaboration technology in meeting spaces can […]

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest Downloads

Practical Design Guide for Office Spaces
Practical Design Guide for Office Spaces

Recent Gartner research shows that workers prefer to return to the office for in-person meetings for relevant milestones, as well as for face-to-fa...

New Camera Can Transform Your Live Production Workflow
New Camera System Can Transform Your Live Production Workflow

Sony's HXC-FZ90 studio camera system combines flexibility and exceptional image quality with entry-level pricing.

Creating Great User Experience and Ultimate Flexibility with Clickshare

Working and collaborating in any office environment today should be meaningful, as workers today go to office for very specific reasons. When desig...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Contact Us
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSYour Privacy ChoicesTERMS OF USEPRIVACY POLICY

© 2025 Emerald X, LLC. All rights reserved.