Software giant's dominance becomes a liability
Sign up now: Get ST's newsletters delivered to your inbox

SolarWinds confirmed that its flagship network management software was involved in an international cyberespionage operation.
PHOTO: REUTERS
WASHINGTON • On an earnings call two months ago, SolarWinds chief executive Kevin Thompson touted how far the company had gone during his 11 years at the helm.
There was not a database or an IT deployment model out there to which his Austin, Texas-based company did not provide some level of monitoring or management, he told analysts on the Oct 27 call.
"We don't think anyone else in the market is really even close in terms of the breadth of coverage we have," he said. "We manage everyone's network gear."
Now that dominance has become a liability - an example of how the workhorse software that helps glue organisations together can turn toxic when it is subverted by sophisticated hackers.
On Monday, SolarWinds confirmed that Orion - its flagship network management software - had served as the unwitting conduit for a sprawling international cyber espionage operation.
The hackers inserted malicious code into Orion software updates pushed out to nearly 18,000 customers. And while the number of affected organisations is thought to be much more modest, the hackers have already parlayed their access into consequential breaches at the US Treasury and Department of Commerce.
Three people familiar with the investigation have told Reuters that Russia is a top suspect, although others familiar with the inquiry have said it is still too early to tell.
SolarWinds representative Ryan Toohey said he would not be making executives available for comment. He did not provide on-the-record answers to questions sent via e-mail.
In a statement issued on Sunday, the company said "we strive to implement and maintain appropriate administrative, physical and technical safeguards, security processes, procedures, and standards designed to protect our customers".
Cyber-security experts are still struggling to understand the scope of the damage.
The malicious updates - sent between March and June, when America was hunkering down to weather the first wave of coronavirus infections - was "perfect timing for a perfect storm", said co-chair Kim Peretti at Atlanta-based law firm Alston & Bird's cyber-security preparedness and response team.
Assessing the damage would be difficult, she said.
The impact on SolarWinds was more immediate.
US officials ordered anyone running Orion to immediately disconnect it. The company's stock has tumbled more than 23 per cent from US$23.50 last Friday - before Reuters broke the news of the breach - to US$18.06 on Tuesday.
REUTERS

