News March 1th, 2021

SolarWinds explains hack: “it’s the intern’s fault”

March 1th, 2021

SolarWinds' Orion network monitoring software, which is used by about 18 of the company's customers, suffered a major hack in 2019. security breach affected 9 US federal agencies, as well as several private companies, such as Microsoft, for example. Now SolarWinds is under investigation by the US government.

The investigation revealed that the password to a company server had been leaked and posted online, which facilitated the hack. To make matters worse, the password was “solarwinds123,” and former company CEO Kevin Thompson claimed the leak was “an intern’s mistake.” according to CNN. “The person violated our password policies and posted that password on their private Github account,” the former CEO said, “as soon as my security team pointed it out, they took the post down.”

But it seems that the US representatives involved in the investigation didn’t buy the story. As California Representative Katie Porter put it: “I have a stronger password than ‘solarwinds123’ to keep my kids from watching too much YouTube on their iPads. You and your company should be stopping the Russians from reading Defense Department emails!”

Security experts believe that thousands of hackers were involved in the SolarWinds hack, which was considered “the largest and most sophisticated cyber attack that the world has ever seen.” The invasion appears to have been carried out from within the US, but some still believe that Russian hackers were primarily responsible for the attack.

The investigation into the SolarWinds hack is focused on whether the cyberattack was due to overly easy passwords, compromised third-party software, or simply the strength of the attack itself on the company's servers.

Through which channels you reach those people, classic and out of the box. Tech Radar

Image: Joan Gamell (Unsplash)

Read too