All cases

SolarWinds (Sunburst)

March 2020 – December 2020

Record reviewed: 2026-07

EspionagePeak: DisruptionAttribution: High ConfidenceGovernmentTechnologyDefense
Year
2020
Actor country
Russia
Target regions
United States, United Kingdom, NATO allies
Unpeace score
8

Executive Summary

Sophisticated supply chain compromise of SolarWinds Orion IT monitoring platform, enabling covert access to ~18,000 organizations including US federal agencies. Discovered in December 2020 after ~9 months of undetected access.

Why This Matters

SolarWinds exposed systemic supply chain risk in government IT and triggered the most sweeping US cybersecurity executive order in a decade, reshaping federal procurement and zero-trust policy.

Escalation Profile

7-Dimension Profile

Escalation Ladder

Probing
Intrusion
Disruption
Degradation
Destruction
Strategic

Phases

2020-03
Intrusion

Supply chain backdoor

Trojanized SolarWinds Orion update delivered SUNBURST backdoor to ~18,000 customers.

2020-05
Intrusion

Selective second-stage targeting

Operators deployed TEARDROP/Cobalt Strike only against ~100 high-value targets including Treasury, Commerce, DHS.

2020-12
Disruption

Discovery and response

FireEye discovered breach via stolen red-team tools; triggered government-wide incident response.

Threshold Crossings

  • Scale of supply chain access exceeded traditional espionage scope
  • Compromised core government IT monitoring infrastructure

Restraint Factors

  • Operated within traditional espionage norms, collection, not disruption
  • Selective targeting minimized footprint

Attribution Assessment

High ConfidenceSVR (Foreign Intelligence Service)
Russia
APT29Cozy BearNobeliumMidnight Blizzard
1. Technical

Threat actor mapped to Russia based on infrastructure analysis, malware attribution, and operational patterns.

Evidence: FireEye/Mandiant: Highly Evasive Attacker Leverages SolarWinds Supply Chain (SUNBURST)

2. Political / Legal
Public AttributionSanctions Imposed
  • Executive Order 14028: Improving the Nation's Cybersecurity (May 2021)
  • US sanctions against Russian entities and expulsion of diplomats (Apr 2021)
  • CISA Emergency Directive 21-01

Sources: CISA Emergency Directive 21-01: Mitigate SolarWinds Orion Code Compromise; Executive Order 14028: Improving the Nation's Cybersecurity

3. Open Source
  • Brad Smith (Microsoft), 'A moment of reckoning: the need for a strong and global cybersecurity response'(2020-12-17)
  • Dina Temple-Raston, 'A “Worst Nightmare” Cyberattack: The Untold Story Of The SolarWinds Hack,' NPR(2021-04-16)

High Confidence” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.

Unpeace Position

8

Unpeace Score

Composite severity rating on the peace–conflict spectrum (1–10)

Stable
Contested
Escalatory
03060100

Unpeace · score breakdown

8/10
Escalation peak3 × 1.2 = +3.6

Peak tier reached (disruption), ranked 1–6.

Threshold crossings2 × 1 = +2

Distinct escalation thresholds the operation crossed.

Governance weight4 × 0.5 = +2

Formal governance responses flagged (attribution, sanctions, indictments…).

Raw sum 7.6= 8/10

round( escalationPeak×1.2 + crossings×1 + governance×0.5 ), capped at 10. These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Entanglement · score breakdown

7/10
Sectors affected3 × 1 = +3

Distinct critical-infrastructure sectors touched.

Countries / regions3 × 1 = +3

Geographic spread of impact.

Threshold crossings2 × 1 = +2

Escalation thresholds crossed (collateral-spread proxy).

Baseline offset1 × -1 = -1

Constant offset so a single-sector, single-country event floors at 1.

Raw sum 7= 7/10

clamp( sectors + countries + crossings − 1, 1, 10 ). These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Coercive Function

Espionage

Intelligence collection, coercive value lies in the information advantage gained and the implicit signal that the adversary can access sensitive systems.

Observed coercive effects

  • Scale of supply chain access exceeded traditional espionage scope
  • Compromised core government IT monitoring infrastructure

Entanglement Risk

Entanglement score7

Sectors affected

GovernmentTechnologyDefense

Countries / regions

United StatesUnited KingdomNATO allies

Impact summary

Covert access to email and files at Treasury, Commerce, DHS, DOE, and ~100 private-sector organizations.

Infrastructure Meaning

Malware / tooling

SUNBURSTTEARDROPCobalt Strike

Capability profile

Covert access to email and files at Treasury, Commerce, DHS, DOE, and ~100 private-sector organizations.

4 ATT&CK techniques mapped — see ATT&CK mapping below.

Governance Analysis

Governance Flags

!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Norms invoked

  • Debate over whether espionage violates UN GGE norms
  • Responsible state behavior in cyberspace (OEWG)

Policy responses

  • Executive Order 14028: Improving the Nation's Cybersecurity (May 2021)
  • US sanctions against Russian entities and expulsion of diplomats (Apr 2021)
  • CISA Emergency Directive 21-01

Regulatory changes

  • Federal zero-trust architecture mandate
  • SBOM requirements for federal software suppliers
  • Cyber Safety Review Board (CSRB) establishment

Governance impact assessment

Catalyzed the most significant US cybersecurity policy overhaul in a decade, establishing zero-trust mandates and supply chain security requirements across the federal government.

Sources

Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.