Cyberattack

Power Grid

SolarWinds supply-chain compromise — U.S. DOE and FERC networks exposed

Disclosed 17 December 2020

Washington, D.C., United States

38.8950, -77.0360

Loading free detailed map…

What happened

The SolarWinds Orion supply-chain compromise reached business networks at the U.S. Department of Energy, including the National Nuclear Security Administration, and affected the Federal Energy Regulatory Commission. DOE said the malware was isolated to business networks and did not affect mission-essential national-security functions; no grid control or generation disruption was reported. The incident exposed sensitive government and regulatory environments, but the supplied claim that attackers obtained a complete 'roadmap' of U.S. grid vulnerabilities is not stated as fact.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Current temperature
Loading…
Latitude
38.8950°
Longitude
-77.0360°

Attribution

Attributed to Russian Foreign Intelligence Service (SVR)

The U.S. government formally attributed the broader SolarWinds supply-chain campaign to the Russian SVR in April 2021.

Sources

  1. DOE update on cyber incident related to SolarWinds compromiseU.S. Department of Energy · Incident reporting
  2. SolarWinds and related supply-chain compromise white paperFederal Energy Regulatory Commission · Energy-regulator exposure and mitigation context