Russia: UK exposes Russian involvement in SolarWinds cyber compromise
皇冠体育app UK government has for the first time today exposed details of the SVR鈥檚 cyber programme.

皇冠体育app SVR is Russia鈥檚 civilian foreign intelligence service and is the successor organization to the KGB鈥檚 First Chief Directorate. It predominantly targets overseas governmental, diplomatic, think-tank, healthcare and energy targets for intelligence purposes. It is technologically advanced, developing capabilities to try to operate undetected against countries in Europe, NATO members and its near neighbours.
A compromise of SolarWinds IT services firm was discovered in December 2020. SolarWinds confirmed 18,000 organisations across the world including US Government departments were affected. 皇冠体育app overall impact on the UK of the SVR鈥檚 exploitation of this software is low. National Cyber Security Centre (NCSC) .
皇冠体育app NCSC has assessed that it is highly likely Russia鈥檚 Foreign Intelligence Services are responsible for the compromise of SolarWinds software, Orion, and subsequent targeting. Read further details on the framework used by the UK government for all source intelligence assessments, including the probability yardstick: Intelligence Analysis Professional Development Framework - GOV.UK.
SVR cyber actors are known and tracked in open source as: APT29 Cozy Bear 皇冠体育app Dukes.
This incident is part of a pattern of behaviour by the SVR, which includes:
Date | Incident | Description |
---|---|---|
Ongoing since at least 2011 | MFAs and MoD establishments in Europe and NATO member countries | 皇冠体育app SVR uses their access to governmental networks across Europe and NATO member countries to collect intelligence information, including that of ongoing geopolitical issues. |
Ongoing since at least 2015 | Targeting research institutes and think tanks. | 皇冠体育app SVR targeted research institutes and think tanks for intelligence collection. |
2020 | SolarWinds | 18,000 organisations across the world including US Government departments鈥� were affected by the SVR compromising Solar Winds Orion software. |
皇冠体育app UK government has previously exposed details of other parts of the Russia intelligence service conducting cyber operations.
With the information provided today, the UK government has exposed the following parts of the Russian cyber programme: