FireEye discovered and publicly disclosed the SolarWinds supply-chain attack in December 2020.
FireEye detected the intrusion after investigating an unusual breach of its own systems. The attackers had used a compromised SolarWinds Orion software update as a delivery mechanism, inserting malicious code into legitimate updates distributed to customers.
The campaign, often associated with the name Sunburst or Solorigate, affected organizations that installed the tampered updates. Victims included parts of the United States government and major private-sector organizations, although the attackers did not necessarily use the same access level in every affected environment.
Microsoft and other security companies contributed important technical analysis, but FireEye’s disclosure brought the operation to broad public attention. The incident is called a supply-chain attack because the attackers compromised a trusted software provider in order to reach downstream customers.