In December 2020, the cybersecurity firm FireEye disclosed that it had been breached. Within days, the investigation revealed something much larger: the attackers had compromised SolarWinds, a widely used IT management platform, and inserted malicious code into a legitimate software update. An estimated 18,000 organisations — including multiple US federal agencies, NATO, the UK’s National Health Service and most of the Fortune 500 — had downloaded and installed the compromised update. The SolarWinds attack was not the first supply chain attack, but it was the largest and most consequential, and it transformed how the technology industry thinks about software security.
The Anatomy of SolarWinds
The SolarWinds attack, attributed by US intelligence agencies to Russia’s SVR foreign intelligence service, was remarkable for its patience and sophistication. The attackers gained access to SolarWinds’ build environment — the servers where software updates are compiled and digitally signed — sometime in 2019. Over the course of months, they inserted a backdoor, dubbed SUNBURST, into the Orion IT monitoring platform, which was then distributed to customers via a routine software update between March and June 2020. The backdoor lay dormant for up to two weeks after installation before activating, communicating with command-and-control servers by disguising its traffic as legitimate SolarWinds API calls. The attackers then selectively targeted a small subset of victims — approximately 100 organisations — for further exploitation, carefully avoiding tripping detection systems.
The financial and operational impact was enormous. SolarWinds’ market capitalisation dropped by roughly $4 billion in the weeks following the disclosure. The company faced shareholder lawsuits, SEC investigations and Congressional hearings. Cybersecurity insurance premiums for software companies increased by an average of 50% in 2021. And the US government’s response — including sanctions on Russian entities and a comprehensive executive order on cybersecurity — signalled that supply chain security had become a matter of national security.
The xz utils Incident: How Close We Came to Catastrophe
In March 2024, a Microsoft software engineer named Andres Freund noticed something odd: SSH connections to his development machine were consuming slightly more CPU than expected. His curiosity led to the discovery of one of the most sophisticated software supply chain attacks ever attempted. A malicious actor, operating under the pseudonym “Jia Tan,” had spent over two years building trust within the open source community, obtaining maintainer access to xz utils — a compression library used by virtually every Linux distribution — and inserting a backdoor into the software’s build process. The backdoor, which was shortly scheduled to be shipped in stable releases of Debian and Red Hat Enterprise Linux, would have enabled remote code execution on millions of internet-facing servers.
The xz utils incident was a near miss of historic proportions. Had the backdoor been deployed to stable Linux distributions, it would have been the most widespread software supply chain compromise in history, potentially exceeding SolarWinds by an order of magnitude. The incident exposed the fragility of the open source supply chain: critical infrastructure, used by billions of people, is maintained by unpaid volunteers who are vulnerable to social engineering and burnout. The xz utils attack prompted a reckoning within the open source community and led to new initiatives, including the Open Source Security Foundation’s effort to provide funding and security reviews for critical open source projects.
The Regulatory Response
Supply chain attacks have catalysed significant regulatory change. The US Executive Order 14028 mandated the development of a Software Bill of Materials (SBOM) — a formal, machine-readable inventory of all components, libraries and dependencies in a software product — for any software sold to the federal government. The Cybersecurity and Infrastructure Security Agency (CISA) has published detailed SBOM guidance, and NIST has incorporated SBOM requirements into its Secure Software Development Framework. The European Union’s Cyber Resilience Act, which entered into force in 2024, goes further, imposing mandatory security requirements and liability for software products sold in the EU market.
The existential question raised by the SolarWinds and xz utils attacks is whether the software industry’s decades-long reliance on trust — trust in vendors, trust in open source maintainers, trust in digital signatures and build pipelines — is sustainable. The answer, as events have demonstrated, is no. The alternative is verifiable trust: cryptographic attestations, reproducible builds (where independent parties can verify that a given binary was produced from a given source code), continuous monitoring of build environments and mandatory isolation between development and production systems. These measures are expensive and complex, which is why they have not been widely adopted. But the cost of not adopting them is increasingly clear. The next supply chain attack is not a question of if, but when — and whether the industry has learned enough to detect it before it becomes another SolarWinds.
