US, UK say Russia was behind SolarWinds hack

President Joe Biden issues sanctions against 32 entities and officials, as well as expelling 10 diplomats

The Russian foreign intelligence service SVR was behind last year’s Solarwinds cyber attack, according to the UK government, confirming the long-standing suspicions made by high-profile US politicians.

The attack, which was discovered in December 2020, affected 18,000 organisations across the world including US government departments such as Homeland Security (DHS).

Russian state-backed hackers were the main suspects for carrying out the compromise, with the Trump administration’s Secretary of State Mike Pompeo stating in December that Russia was “clearly” behind the attack. A month later, the US government issued a statement claiming that the advanced persistent threat (APT) actor behind the incident is “likely Russian in origin”.

This week, the UK’s National Cyber Security Centre (NCSC) confirmed the US’ suspicions, finding it “highly likely the SVR was responsible for gaining unauthorised access to SolarWinds “Orion” software and subsequent targeting”. The Foreign, Commonwealth and Development Office (FCDO) has also summoned the Russian Ambassador over the UK government’s “deep concern at a pattern of malign activity, including cyber intrusions”.

To coincide with the UK government's statement, US president Joe Biden also announced new sanctions against Russia, targeting 32 entities and officials, as well as expelling 10 diplomats.

According to the president, the sanctions were “proportionate” and in response to the Solarwinds incident as well as Russia’s attempts to influence the 2020 US presidential election "and other acts of disinformation".

"I was clear with President Putin that we could have gone further, but I chose not to do so. The United States is not looking to kick off a cycle of escalation and conflict with Russia,” said Biden.

FCDO permanent under secretary, Sir Philip Barton, “made clear the UK’s support for the actions announced by President Biden in response to Russia’s recent activity”, according to a FCDO spokesperson.

Barton “set out the UK assessment that the Russian Intelligence Services were behind the SolarWinds compromise” and has “informed the Ambassador that the UK will continue to work with our allies to call out and counter malign operations by the Russian Intelligence Services”.

“Sir Philip also stated the UK’s concern at the build up of Russian military forces near the Ukrainian border and illegally-annexed Crimea. These activities are threatening and destabilising. Russia needs to cease its provocations and de-escalate tensions in line with its international obligations,” the FCDO spokesperson added.

Commenting on the NCSC’s findings, Foreign Secretary Dominic Raab, said that the UK and US governments “are calling out Russia’s malicious behaviour, to enable our international partners and businesses at home to better defend and prepare themselves against this kind of action”.

Raab also vowed that the UK will “continue to work with allies to call out Russia’s malign behaviour where we see it”.

Featured Resources

BCDR buyer's guide for MSPs

How to choose a business continuity and disaster recovery solution

Download now

The definitive guide to IT security

Protecting your MSP and your customers

Download now

Cost of a data breach report 2020

Find out what factors help mitigate breach costs

Download now

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Recommended

New report highlights the need for diversity in cyber security recruitment
cyber security

New report highlights the need for diversity in cyber security recruitment

28 Apr 2021
Data breach exposes widespread fake reviews on Amazon
data breaches

Data breach exposes widespread fake reviews on Amazon

7 May 2021
TsuNAME vulnerability could enable DDoS attacks on major DNS servers
distributed denial of service (DDOS)

TsuNAME vulnerability could enable DDoS attacks on major DNS servers

7 May 2021
What are SSH keys?
cyber security

What are SSH keys?

7 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021