SolarWinds Supply Chain Attack: The Largest Cyber Espionage in History
May 29, 2026, 7:36 p.m.

SolarWinds Supply Chain Attack: The Largest Cyber Espionage Operation in History

The SolarWinds supply chain attack that emerged in December 2020 has been recorded as one of the most sophisticated and impactful operations in cybersecurity history. Affecting thousands of organizations and particularly targeting US federal agencies, this attack once again highlighted the critical importance of supply chain security. In this comprehensive review, we will examine in detail the anatomy of the attack, its impacts, and the lessons it taught the corporate world.

What is the SolarWinds Attack and How Did It Happen?

Tedarik zinciri saldırısı görselleştirmesi
Supply chain attack visualization

SolarWinds Corporation is a technology company that provides network and infrastructure management software to over 300,000 customers worldwide. The attackers targeted one of the company's most popular products, the Orion Platform, infiltrating thousands of organizations through a trusted software update.

The attack used a method known as a supply chain compromise. Rather than targeting organizations directly, the attackers targeted a third-party software supplier that these organizations trusted. This approach is considered one of the most effective ways to bypass cybersecurity defenses.

SUNBURST and SUNSPOT Malware

At the center of the attack were two significant malware components:

SUNBURST (also known as Solorigate) is malicious code that appeared to be a legitimate component of SolarWinds Orion software but actually functioned as a backdoor. This malware had the following characteristics on affected systems:

  • A two-week dormancy period to avoid detection
  • Command-and-control communication hidden within legitimate SolarWinds traffic
  • Selective behavior: Only becoming active on valuable targets
  • Ability to detect and disable security tools and processes
  • Mechanisms for cleaning traces and self-concealment

SUNSPOT is another malware that explains how attackers infiltrated SolarWinds' build process. SUNSPOT was planted in SolarWinds' software development environment, monitoring the compilation process of Orion software and automatically inserting SUNBURST code. This is one of the most important indicators of how planned and sophisticated the attack was.

Chronology and Anatomy of the Attack

According to analyses by FireEye and Microsoft security researchers, the timeline of the attack unfolded as follows:

September 2019 - February 2020: Attackers infiltrated SolarWinds' internal network and explored the software development environment. During this period, they planted the SUNSPOT malware.

March 2020: The first Orion update containing SUNBURST (2019.4 HF 5) was released. However, the malicious code was not fully active in this version.

May 2020: Orion updates containing the fully functional version of SUNBURST (2019.4 HF 6 and 2020.2) were released. This was distributed to approximately 18,000 SolarWinds customers.

June - November 2020: Attackers monitored infected systems and identified valuable targets. They conducted second-stage attacks on approximately 100 organizations.

December 2020: FireEye detected abnormal activity in its own systems and launched an investigation. This led to the discovery of the attack.

Affected Organizations and Scale of the Attack

Dünya çapında etkilenen kurumların haritası
Map of affected organizations worldwide

The impact scope of the SolarWinds attack was truly striking. Approximately 18,000 organizations installed updates containing the malware. However, the attackers focused their resources on the most valuable targets and conducted in-depth attacks on approximately 100 organizations.

Impact on US Federal Agencies

Among the most critical institutions affected by the attack were:

  • US Department of Treasury: Unauthorized access was gained to email systems
  • US Department of Commerce: National Telecommunications and Information Administration data was compromised
  • US Department of Energy: Units responsible for nuclear security systems were affected
  • US Department of State: Diplomatic communication and email systems were put at risk
  • Department of Homeland Security: The very agency responsible for cybersecurity was targeted
  • Pentagon and Defense Circle: Various defense contractors and affiliated organizations

In the private sector, Fortune 500 companies such as Microsoft, Cisco, Intel, Nvidia, and Deloitte were also targeted. The theft of cybersecurity firm FireEye's own attack tools demonstrated the seriousness of the situation.

International Dimension and Turkey Connection

The attack was not limited to the US. Affected organizations were also identified in countries such as Canada, the United Kingdom, Israel, Mexico, Belgium, and the UAE. In Turkey, some large organizations using SolarWinds products were assessed to be at potential risk.

Although some Turkish public institutions and private sector companies use the SolarWinds Orion platform, no large-scale data breach was reported in Turkey. However, this situation prompted local organizations to question themselves about supply chain security and review their risk assessments.

Attribution of the Attack: APT29 and Russian Connection

The US intelligence community and leading cybersecurity firms attributed the attack with high confidence to APT29 (Advanced Persistent Threat 29), a threat actor believed to be linked to Russia's Foreign Intelligence Service (SVR). APT29 is also known by the aliases "Cozy Bear" or "The Dukes."

This attribution is based on characteristics such as the attack's technical sophistication, target selection, patient approach, and national-level intelligence gathering purpose. Russian officials have consistently denied these allegations.

Critical Lessons and Recommendations for Turkey

The SolarWinds attack contains important lessons for Turkish organizations. As Nordis Global, in light of this incident, we offer the following recommendations:

1. Supply Chain Risk

Similar Posts