Russian SVR foreign intelligence (APT29 / Cozy Bear / Nobelium) compromised the build pipeline of SolarWinds' Orion IT-monitoring platform in late 2019, inserting a trojanized DLL (SUNBURST) into a signed software update distributed to approximately 18,000 customers. Of those, roughly 100 high-value targets were enumerated for deeper intrusion, including nine US federal agencies — Treasury, Commerce, State, DHS, and others — as well as Microsoft, FireEye, and Mimecast. FireEye disclosed the attack on 8 December 2020 after discovering its own breach. CISA issued Emergency Directive 21-01 on 13 December 2020. The operation is one of the most significant intelligence-gathering cyber-intrusions ever documented against the United States government.