HOME

TheInfoList



OR:

SolarWinds Corporation is an American company that develops software for businesses to help manage their
networks Network, networking and networked may refer to: Science and technology * Network theory, the study of graphs as a representation of relations between discrete objects * Network science, an academic field that studies complex networks Mathematics ...
,
systems A system is a group of interacting or interrelated elements that act according to a set of rules to form a unified whole. A system, surrounded and influenced by its environment, is described by its boundaries, structure and purpose and is exp ...
, and
information technology Information technology (IT) is a set of related fields within information and communications technology (ICT), that encompass computer systems, software, programming languages, data processing, data and information processing, and storage. Inf ...
infrastructure. It is headquartered in
Austin, Texas Austin ( ) is the List of capitals in the United States, capital city of the U.S. state of Texas. It is the county seat and most populous city of Travis County, Texas, Travis County, with portions extending into Hays County, Texas, Hays and W ...
, with sales and product development offices in a number of locations in the United States and several other countries. The company was publicly traded from May 2009 until the end of 2015, and again from October 2018. It has also acquired a number of other companies, some of which it still operates under their original names, including Pingdom, Papertrail, and Loggly. It had about 300,000 customers as of December 2020, including nearly all ''Fortune'' 500 companies and numerous agencies of the US federal government. A SolarWinds product, Orion, used by about 33,000 public and private sector customers, was the focus of a U.S. federal government data leak in 2020. The attack persisted undetected for months in 2020, and additional details about the breadth and depth of compromised systems continued to surface after the initial disclosure. In February 2021,
Microsoft Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
President Brad Smith said that it was "the largest and most sophisticated attack the world has ever seen".


History

SolarWinds began in 1999 in
Tulsa, Oklahoma Tulsa ( ) is the List of municipalities in Oklahoma, second-most-populous city in the U.S. state, state of Oklahoma, after Oklahoma City, and the List of United States cities by population, 48th-most-populous city in the United States. The po ...
, co-founded by Donald Yonce (a former executive at
Walmart Walmart Inc. (; formerly Wal-Mart Stores, Inc.) is an American multinational retail corporation that operates a chain of hypermarkets (also called supercenters), discount department stores, and grocery stores in the United States and 23 other ...
) and his brother Dave Yonce. SolarWinds released its first products, Trace Route and Ping Sweep, earlier in March 1998 and released its first web-based
network performance Network performance refers to measures of service quality of a network as seen by the customer. There are many different ways to measure the performance of a network, as each network is different in nature and design. Performance can also be mod ...
monitoring application in November 2001. In 2006, the company moved its headquarters to
Austin, Texas Austin ( ) is the List of capitals in the United States, capital city of the U.S. state of Texas. It is the county seat and most populous city of Travis County, Texas, Travis County, with portions extending into Hays County, Texas, Hays and W ...
, where about 300 of the company's total 450 employees were based as of 2011. The company was profitable from its founding through its IPO in 2009. During 2007, SolarWinds raised funding from Austin Ventures,
Bain Capital Bain Capital, LP is an American Investment company, private investment firm based in Boston, Massachusetts, Boston, Massachusetts, with around $185 billion of assets under management. It specializes in private equity, venture capital, credit, p ...
, and Insight Venture Partners. SolarWinds completed an
initial public offering An initial public offering (IPO) or stock launch is a public offering in which shares of a company are sold to institutional investors and usually also to retail (individual) investors. An IPO is typically underwritten by one or more investm ...
of
US$ The United States dollar (Currency symbol, symbol: Dollar sign, $; ISO 4217, currency code: USD) is the official currency of the United States and International use of the U.S. dollar, several other countries. The Coinage Act of 1792 introdu ...
112.5 million in May 2009, closing at higher prices after its initial day of trading. The IPO from SolarWinds was followed by another from OpenTable (an online restaurant-reservation service), which was perceived to break a dry spell during the
Great Recession The Great Recession was a period of market decline in economies around the world that occurred from late 2007 to mid-2009.
, when very few companies went public. Both Bain Capital and Insight Venture Partners backed the IPO and used the opportunity to sell some of their shares during the offering. Analysts and company executives anticipated continued expansion post-IPO, including several acquisitions. In 2010, Bennett retired as CEO and was replaced by the company's former chief financial officer Kevin Thompson. In May 2013, SolarWinds announced plans to invest in an operations hub in
Salt Lake City, Utah Salt Lake City, often shortened to Salt Lake or SLC, is the List of capitals in the United States, capital and List of cities and towns in Utah, most populous city of the U.S. state of Utah. It is the county seat of Salt Lake County, Utah, Salt ...
. It was named by ''
Forbes ''Forbes'' () is an American business magazine founded by B. C. Forbes in 1917. It has been owned by the Hong Kong–based investment group Integrated Whale Media Investments since 2014. Its chairman and editor-in-chief is Steve Forbes. The co ...
'' as "Best Small Company in America, citing high-functioning products for low costs and impressive company growth." By 2013, SolarWinds employed about 900 people. Acquisition by private equity technology investment firms Silver Lake Partners and
Thoma Bravo Thoma Bravo, LP is an American private equity and growth capital firm based in Chicago, Illinois. It is known for being particularly active in acquiring enterprise software companies and has over $130billion in assets under management . It ...
, LLC. was announced in late 2015, and by January 2016, SolarWinds was taken private in a $4.5 billion deal. At the time, the company had 1,770 employees worldwide with 510 based in Austin, and reported revenues of about half a billion dollars a year. In November 2017, SolarWinds released AppOptics which integrates much of their software portfolio, including Librato and TraceView, into a single
software-as-a-service Software as a service (SaaS ) is a cloud computing service model where the provider offers use of application software to a client and manages all needed physical and software resources. SaaS is usually accessed via a web application. Unlike oth ...
package. AppOptics included compatibility with
Amazon Web Services Amazon Web Services, Inc. (AWS) is a subsidiary of Amazon.com, Amazon that provides Software as a service, on-demand cloud computing computing platform, platforms and Application programming interface, APIs to individuals, companies, and gover ...
and
Microsoft Azure Microsoft Azure, or just Azure ( /ˈæʒər, ˈeɪʒər/ ''AZH-ər, AY-zhər'', UK also /ˈæzjʊər, ˈeɪzjʊər/ ''AZ-ure, AY-zure''), is the cloud computing platform developed by Microsoft. It has management, access and development of ...
. In September 2018, SolarWinds filed for a public offering again, after three years of being owned by private equity firms. SolarWinds completed their public offering on October 19, 2018. On December 7, 2020, CEO Kevin Thompson retired, to be replaced by Sudhakar Ramakrishna, CEO of Pulse Secure, effective January 4, 2021. On January 8, 2021, SolarWinds hired former CISA director Chris Krebs to help the company work through the recent cyber attack. In July 2021, SolarWinds separated its managed service provider (MSP) business from the main company. The new separately-traded public company is named N-able. In February 2025, the company announced that it would be acquired by
private equity firm A private equity firm or private equity company (often described as a financial sponsor) is an investment management company that provides financial backing and makes investments in the private equity of a Startup company, startup or of an existin ...
Turn/River Capital for $4.4 billion; the deal received approval from
Thoma Bravo Thoma Bravo, LP is an American private equity and growth capital firm based in Chicago, Illinois. It is known for being particularly active in acquiring enterprise software companies and has over $130billion in assets under management . It ...
and Silver Lake, SolarWinds' majority shareholders with a combined 65% of the outstanding voting securities. The deal was closed on April 18, 2025 for $18.50 per share and the company delisted from the
New York Stock Exchange The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District, Manhattan, Financial District of Lower Manhattan in New York City. It is the List of stock exchanges, largest stock excha ...
.


Acquisitions

According to ''
The Wall Street Journal ''The Wall Street Journal'' (''WSJ''), also referred to simply as the ''Journal,'' is an American newspaper based in New York City. The newspaper provides extensive coverage of news, especially business and finance. It operates on a subscriptio ...
'', SolarWinds offers freely downloadable software to potential clients and then markets more advanced software to them by offering trial versions. Following the funding in 2007, SolarWinds acquired several companies including Neon Software and ipMonitor Corp. and opened a European sales office in Ireland. During and after its IPO in 2009, SolarWinds acquired a number of other companies and products, including the acquisition of the New Zealand–based software maker Kiwi Enterprises, which was announced in January 2009. SolarWinds acquired several companies in 2011 and was ranked number 10 on ''Forbes'' magazine's list of fastest-growing tech companies. In January 2011, it acquired Hyper9 Inc, an Austin-based
virtualization In computing, virtualization (abbreviated v12n) is a series of technologies that allows dividing of physical computing resources into a series of virtual machines, operating systems, processes or containers. Virtualization began in the 1960s wit ...
management company with undisclosed terms. In July, SolarWinds completed the acquisition of the Idaho-based network security company TriGeo for $35 million. TriGeo's offices in Post Falls were added to the list of SolarWinds location which already included satellite offices in
Dallas Dallas () is a city in the U.S. state of Texas and the most populous city in the Dallas–Fort Worth metroplex, the List of Texas metropolitan areas, most populous metropolitan area in Texas and the Metropolitan statistical area, fourth-most ...
, Salt Lake City, and Tulsa, as well as operations in Australia, the Czech Republic, India, Ireland, and Singapore. In 2012 SolarWinds acquired the patch management software provider EminentWare, and RhinoSoft, adding the latter company's FTP Voyager product to SolarWinds' product suite. In early 2013, SolarWinds acquired N-able Technologies, a cloud-based
information technology Information technology (IT) is a set of related fields within information and communications technology (ICT), that encompass computer systems, software, programming languages, data processing, data and information processing, and storage. Inf ...
services provider. The deal was reportedly valued $120 million in cash. In late 2013, it acquired the
Boulder, Colorado Boulder is a List of municipalities in Colorado#Home rule municipality, home rule city in Boulder County, Colorado, United States, and its county seat. With a population of 108,250 at the 2020 United States census, 2020 census, it is the most ...
–based database performance management company Confio Software. With the $103 million agreement, SolarWinds gained a sales office in London and Confio's main product, Ignite. Between 2014 and 2015, the company acquired the Swedish web-monitoring company Pingdom, the San Francisco–based metrics and monitoring company Librato (for $40 million), and the log management service Papertrail (for $41 million). Between 2015 and 2020, SolarWinds acquired Librato (a monitoring company), Capzure Technology (an MSP Manager software to N-able which SolarWinds had previously acquired), LogicNow (a remote monitoring software company), SpamExperts (an email security company), Loggly (a log management and analytics company), Trusted Metrics (a provider of threat monitoring and management software), Samanage (a service desk and IT asset management provider), VividCortex (a database performance monitor), and SentryOne (a provider of database performance monitoring).


2019–2020 supply chain attacks


SUNBURST

On December 13, 2020, ''
The Washington Post ''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
'' reported that multiple government agencies were breached through SolarWinds's Orion software. The next day, the company stated in an SEC filing that fewer than 18,000 of its 33,000 Orion customers were affected, involving certain hotfixes of versions 2019.4 through 2020.2.1, released between March 2020 and June 2020. According to
Microsoft Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
, hackers acquired
superuser In computing, the superuser is a special user account used for system administration. Depending on the operating system (OS), the actual name of this account might be root, administrator, admin or supervisor. In some cases, the actual name of the ...
access to SAML token-signing certificates. This SAML certificate was then used to forge new tokens to allow hackers trusted and highly privileged access to networks. The Cybersecurity and Infrastructure Security Agency issued Emergency Directive 21–01 in response to the incident, advising all federal civilian agencies to disable Orion. APT29, aka Cozy Bear, working for the Russian Foreign Intelligence Service ( SVR), was reported to be behind the 2020 attack. Victims of this attack include the cybersecurity firm FireEye, the
US Treasury Department The Department of the Treasury (USDT) is the national treasury and finance department of the federal government of the United States. It is one of 15 current U.S. government departments. The department oversees the Bureau of Engraving and ...
, the
US Department of Commerce The United States Department of Commerce (DOC) is an executive department of the U.S. federal government. It is responsible for gathering data for business and governmental decision making, establishing industrial standards, catalyzing econo ...
's
National Telecommunications and Information Administration The National Telecommunications and Information Administration (NTIA) is a bureau of the United States Department of Commerce that serves as the president's principal adviser on telecommunications policies pertaining to the United States' ec ...
, as well as the US Department of Homeland Security. Prominent international SolarWinds customers investigating whether they were impacted include the
North Atlantic Treaty Organization The North Atlantic Treaty Organization (NATO ; , OTAN), also called the North Atlantic Alliance, is an intergovernmental transnational military alliance of 32 member states—30 European and 2 North American. Established in the aftermat ...
(NATO), the
European Parliament The European Parliament (EP) is one of the two legislative bodies of the European Union and one of its seven institutions. Together with the Council of the European Union (known as the Council and informally as the Council of Ministers), it ...
, UK
Government Communications Headquarters Government Communications Headquarters (GCHQ) is an intelligence and security organisation responsible for providing signals intelligence (SIGINT) and information assurance (IA) to the government and armed forces of the United Kingdom. Primari ...
, the UK
Ministry of Defence A ministry of defence or defense (see American and British English spelling differences#-ce.2C -se, spelling differences), also known as a department of defence or defense, is the part of a government responsible for matters of defence and Mi ...
, the UK National Health Service (NHS), the UK Home Office, and
AstraZeneca AstraZeneca plc () (AZ) is a British-Swedish multinational pharmaceutical and biotechnology company with its headquarters at the Cambridge Biomedical Campus in Cambridge, UK. It has a portfolio of products for major diseases in areas includi ...
. FireEye reported the hackers inserted "malicious code into legitimate software updates for the Orion software that allow an attacker remote access into the victim's environment" and that they have found "indications of compromise dating back to the spring of 2020". FireEye named the malware SUNBURST. Microsoft called it Solorigate. The attack used a backdoor in a SolarWinds
library A library is a collection of Book, books, and possibly other Document, materials and Media (communication), media, that is accessible for use by its members and members of allied institutions. Libraries provide physical (hard copies) or electron ...
; when an update to SolarWinds occurred, the malicious attack would go unnoticed due to the trusted certificate. In November 2019, a security researcher notified SolarWinds that credentials to a third party FTP server had a weak password of "solarwinds123", warning that "any hacker could upload malicious
ode An ode (from ) is a type of lyric poetry, with its origins in Ancient Greece. Odes are elaborately structured poems praising or glorifying an event or individual, describing nature intellectually as well as emotionally. A classic ode is structu ...
that would then be distributed to SolarWinds customers. ''The New York Times'' reported SolarWinds did not employ a chief information security officer and that employee passwords had been posted on
GitHub GitHub () is a Proprietary software, proprietary developer platform that allows developers to create, store, manage, and share their code. It uses Git to provide distributed version control and GitHub itself provides access control, bug trackin ...
in 2019. On December 15, 2020, SolarWinds reported the breach to the Securities and Exchange Commission. However, SolarWinds continued to distribute malware-infected updates, and did not immediately revoke the compromised digital certificate used to sign them. On December 16, 2020, German IT news portal Heise.de reported that SolarWinds had for some time been encouraging customers to disable
anti-malware Antivirus software (abbreviated to AV software), also known as anti-malware, is a computer program used to prevent, detect, and remove malware. Antivirus software was originally developed to detect and remove computer viruses, hence the name ...
tools before installing SolarWinds products. On December 17, 2020, SolarWinds said they would revoke the compromised certificates by December 21, 2020. On December 21, 2020, Attorney General William Barr stated that he believed that the SolarWinds hack appears to have been perpetrated by Russia, contradicting speculations by President Donald Trump that China, not Russia, might be to blame. In late December 2020, Trustwave, a cybersecurity firm, reached out to SolarWinds to report new security flaws they had discovered in software produced by SolarWinds. Although these vulnerabilities hadn't been taken advantage of by hackers, it raised questions concerning the network security of SolarWinds' customers. The magnitude of the monetary damage has yet to be calculated, but on January 14, 2021, CRN.com reported that the attack could cost cyber insurance firms at least $90 million. On March 1, 2021, SolarWinds CEO, Sudhakar Ramakrishna, blamed a company intern for using an insecure password ("solarwinds123") on their update server. Speculation that this led to the attack is discounted by the company and security professionals. More than the intern using a weak password, experts noted that the main issue this fact highlights is the poor security culture the company has. In the aftermath of the incident there has been question raised within the US Government about the role Microsoft carried out in enabling the breach. This relates to the "golden SAML" vulnerability in Microsoft's directory offerings that the company had knowledge of but did not address. Senator Ron Wyden questioned why the US Government spent so much money on Microsoft software without the company warning it of this hacking technique.


SUPERNOVA

On December 19, 2020, Microsoft said that its investigations into supply chain attacks at SolarWinds had found evidence of an attempted supply chain attack distinct from the attack in which SUNBURST malware was inserted into Orion binaries (see previous section). This second attack has been dubbed SUPERNOVA. Security researchers from Palo Alto Networks said the SUPERNOVA malware was implemented stealthily. SUPERNOVA comprises a very small number of changes to the Orion source code, implementing a web shell that acts as a remote access tool. The shell is assembled in-memory during SUPERNOVA execution, thus minimizing its forensic footprint. Unlike SUNBURST, SUPERNOVA does not possess a digital signature. This is among the reasons why it is thought to have originated with a different group than the one responsible for SUNBURST.


Insider trading claims

SolarWinds's share price fell 25% within days of the SUNBURST breach becoming public knowledge, and 40% within a week. Insiders at the company had sold approximately $280 million in stock shortly before this became publicly known, which was months after the attack had started. A spokesperson said that those who sold the stock had not been aware of the breach at the time.


Microsoft guidance on service provider and downstream business attacks

In November 2021 Microsoft issued an alert in relation to the advanced persistent threat (APT) actor Nobelium (aka APT29; Cozy Bear) that was responsible for the 2020 SolarWinds supply chain attack is targeting cloud service providers (CSPs), managed service providers (MSPs), and other IT service providers. Microsoft Threat Intelligence Center (MSTIC) released a range of recommendations for service providers and downstream businesses to implement in order to address the threat.


Class action lawsuit

In January 2021, a class action lawsuit was filed against SolarWinds in relation to its security failures and subsequent fall in share price. SolarWinds attempted to have this case dismissed; in March 2022, a judge ruled that the class action lawsuit could move forward. SolarWinds settled the suit for $26 million in November 2022, and was notified by the SEC that it intended to take enforcement action.


References


External links

* {{Authority control Companies based in Austin, Texas Companies listed on the New York Stock Exchange Cross-platform software File transfer protocols File transfer software Network analyzers Network management Networking companies of the United States Port scanners Private equity portfolio companies Software companies based in Texas Software companies established in 1999 Software companies of the United States System administration TPG Capital companies 1999 establishments in Oklahoma 2009 initial public offerings 2015 mergers and acquisitions 2018 initial public offerings American companies established in 1999 Announced mergers and acquisitions