Skip to main content

Fact check

Is it true: SolarWinds Sunburst supply-chain attack (2019-20)?

Confirmed5% confidence

Yes — this is confirmed.

FireEye disclosed the attack on 8 December 2020 after discovering its own breach. CISA Emergency Directive 21-01 (13 December 2020) ordered immediate disconnection of all federal SolarWinds Orion deployments. The US intelligence community, Microsoft (Nobelium), and allied services formally attributed the operation to Russian SVR (APT29 / Cozy Bear). Approximately 18,000 customers received the trojanized update; ~100 high-value targets were enumerated for deeper intrusion including nine US federal agencies.

The claim

Russian SVR foreign intelligence (APT29 / Cozy Bear / Nobelium) compromised the build pipeline of SolarWinds' Orion IT-monitoring platform in late 2019, inserting a trojanized DLL (SUNBURST) into a si

Key evidence

FireEye technical disclosure: SUNBURST backdoor identified Dec 2020

Some researchers initially questioned attribution speed — subsequently resolved

Read the full evidence file

Conspirafy steelmans each claim, then follows the evidence. How we reach a verdict · Check another claim