# SolarWinds Compromise **Domain:** Cybersecurity / Supply-Chain Security / Espionage **Doc Type:** Historical Incident Node **Maturity:** Canonical ## Definition The **SolarWinds compromise** was a large-scale software-supply-chain intrusion disclosed in December 2020. Malicious code inserted into trusted Orion software updates reached U.S. government agencies and private organizations among thousands of downstream customers. ## Significance The incident demonstrated that a trusted administrative update could become an access channel across many otherwise separate networks and forced affected agencies to disconnect or remove compromised products. ## Sources / Provenance - [CISA Emergency Directive 21-01](https://www.cisa.gov/emergency-directive-21-01) - [CISA Alert AA20-352A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a) ## See Also [[wiki/Supply Chain Compromise|Supply Chain Compromise]], [[wiki/Advanced Persistent Threat|Advanced Persistent Threat]], [[wiki/Cyber Attribution|Cyber Attribution]]