Skip to main content
Guidance

NCSC Annual Review 2021

Making the UK the safest place to live and work online

Page 10 of 44

SolarWinds

In April 2021 the NCSC, together with its security counterparts in the US, revealed for the first time that Russia’s Foreign Intelligence Service (SVR) was behind one of the most serious cyber intrusions of recent times, an attack on the popular SolarWinds IT management platform.

This major attribution came five months after the first warning by the NCSC that SolarWinds had been compromised and could be used for further attacks on connected systems.

A US cyber security firm, FireEye, found that an attacker had been able to add a malicious modification to SolarWinds Orion products which allowed them to send administrator-level commands to any affected installation. NCSC, working with colleagues in the US and across industry, investigated the impact of this incident.

When the attack became apparent, NCSC analysts used data from ACD services to estimate the extent of the incident, inform decision-makers in government, and support affected organisations.

The Protective Domain Name System allowed the NCSC to immediately identify historical evidence of compromise of customer organisations, while the Host Based Capability service provided the ability to build a more detailed view of affected devices and activity on customer networks.

The NCSC was able to identify which organisations and sectors were affected to help further the investigation and to help make contact and provide technical advice and support.

Investigators assessed that it was highly likely that the SVR was responsible for the attack and subsequent targeting. At the same time a technical advisory with mitigation advice was issued by the NCSC, in partnership with the US National Security Agency (NSA), Department of Homeland Security’s Cybersecurity Infrastructure Security Agency (CISA) and the FBI.

Published

Reviewed

Version

1.0

Written for