US government: SolarWinds hack affected at least 100 companies and 9 governments
The SolarWinds hack affected at least 100 companies and nine government agencies, the US government says after its own investigation. The number could rise, but is below previous estimates of the number of companies affected.
The investigation into the SolarWinds hack will continue for several months, says Anne Neuberger, who advises in the Biden administration on new technologies. So far, it has emerged that nine federal government agencies and 100 companies have been affected by the hack. Approximately 18,000 SolarWinds customers have downloaded the update containing the malware.
The estimate is below that of early January, when The New York Times reported that at least 250 companies and government agencies would be affected. Neuberger does say the number of known affected companies could rise as the investigation progresses.
The SolarWinds hack came to light in December. Malicious persons, according to Neuberger possibly Russian state hackers, placed malware in an update to Orion, network management software from SolarWinds. This gave the hackers the opportunity to penetrate a company’s network.
Among the affected companies is Microsoft; the company says some of its source codes have been accessed, but only with read access, and it’s unclear if the code was exported. Cisco, Belkin, VMware and Intel were also affected by the hack.