Menu
Browse

Cyber Incident Victim: National Institutes of Health

Date:

Dec 2020

Location:

United States of America

Summary

A state-sponsored supply chain attack compromised the SolarWinds Orion platform, enabling threat actors to breach multiple US government agencies including the Department of Health's National Institutes of Health, alongside other federal entities and private sector organizations. The attackers leveraged trojanized software updates to infiltrate victim networks, with evidence suggesting lateral movement to Microsoft's systems and potential use of its infrastructure for further attacks, though Microsoft denied unauthorized access to its production services or customer data. The incident impacted critical infrastructure and government operations, with cybersecurity firms FireEye and Microsoft collaborating to disrupt the command-and-control infrastructure associated with the campaign.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 3 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

The SolarWinds supply chain compromise, attributed to state-sponsored actors, began with the insertion of malicious code into legitimate updates for the SolarWinds Orion network monitoring platform. This trojanized software was distributed to customers between March and June 2020, enabling attackers to establish footholds within victim networks. The US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on December 17, 2020, confirming the campaign's impact across federal agencies, critical infrastructure, and private organizations. Among the affected entities was the US Department of Health's National Institutes of Health (NIH), compromised through the installation of backdoored Orion software. Attackers leveraged initial access to pivot laterally, with evidence suggesting they exploited Microsoft's corporate environment to stage subsequent attacks against other targets using the technology giant's own products.

Cyber Incident Image

Microsoft confirmed finding malicious SolarWinds binaries in its systems but denied production system compromises or customer data exposure. FireEye and Microsoft led initial disclosures about the campaign on December 13, 2020, and collaborated to disrupt attacker command-and-control infrastructure by sinkholing a critical domain. The incident impacted at least nine federal agencies including NIH, the Departments of Treasury, State, Energy, Homeland Security, and Commerce's NTIA, alongside three US state governments and cybersecurity firm FireEye. CISA noted additional intrusion vectors beyond the Orion platform, though specifics weren't disclosed. Response actions centered on isolating infected systems, removing compromised SolarWinds components, and conducting forensic reviews. No public evidence detailed data exfiltration or operational disruption at NIH specifically, mirroring the broader pattern where most agencies disclosed compromise without confirming downstream impacts.

Sources
Sources available to members
1 source