London Daily

Focus on the big picture.
Monday, Feb 16, 2026

Why the US government hack is literally keeping security experts awake at night

Why the US government hack is literally keeping security experts awake at night

The US government is reeling from multiple data breaches at top federal agencies, the result of a worldwide hacking campaign with possible ties to Russia. Investigators are still trying to figure out how much of the government may have been affected and how badly it may have been compromised.

But what little we know has cybersecurity experts extremely worried — with some describing the attack as a literal wakeup call.

"I woke up in the middle of the night last night just sick to my stomach," said Theresa Payton, who served as White House Chief Information Officer under President George W. Bush. "On a scale of 1 to 10, I'm at a 9 — and it's not because of what I know; it's because of what we still don't know."

On Sunday evening, the Commerce Department acknowledged it had been hit by a data breach after Reuters first reported that sophisticated hackers compromised the agency through a third-party software vendor known as SolarWinds. While SolarWinds is not a household name, it works with many businesses and organizations that are.

Since then, more details have emerged suggesting a much wider pattern of compromise. As many as 18,000 SolarWinds customers — out of a total of 300,000 — may have been running software containing the vulnerability that allowed the hackers to penetrate the Commerce Department, the company disclosed in an investor filing this week.

Here's why the cyberattacks disclosed this week are keeping experts up at night — based on who was targeted, the suspected identities of the attackers and their playbook, according to analysts contacted by CNN Business and published security reports.

All federal agencies on alert


One reason the attack is so concerning is because of who may have been victimized by the spying campaign.

At least three US agencies have publicly confirmed they were compromised: The Department of Commerce, the Department of Homeland Security and the Agriculture Department.

But the range of potential victims is much, much larger, raising the troubling prospect that the US military, the White House or public health agencies responding to the pandemic may have been targeted by the foreign spying, too. The Justice Department, the National Security Agency and even the US

Postal Service have all been cited by security experts as potentially vulnerable.

All federal civilian agencies have been told to review their systems in an emergency directive by DHS officials. It's only the fifth such directive to be issued by the Cybersecurity and Infrastructure Security Agency since it was created in 2015.

It isn't just the US government in the crosshairs: The elite cybersecurity firm FireEye, which itself was a victim of the attack, said companies across the broader economy were vulnerable to the spying, too. The software vulnerability that enabled the spying has been found in the tech and telecom industry, as well as at consulting firms and energy companies, according to FireEye.

Security experts say this is merely the beginning. In the coming days, we may learn that many more companies and agencies have been compromised than we initially suspected. And we still don't know what information may have been lost or stolen.

Extraordinarily skilled attackers


Another reason to worry is that the attackers appear to have been extraordinarily skilled and determined.

"The campaign demonstrates top-tier operational tradecraft and resourcing consistent with state-sponsored threat actors," FireEye said, adding that the breaches appear to date as far back as the spring. "Each of the attacks require meticulous planning and manual interaction."

Attributing any cyberattack is hard under the best of circumstances and even more challenging when a sophisticated actor works to cover their tracks, as these did. But US officials have tentatively said that the culprit may have links to Russia.

That agents of a foreign government may have been responsible for the breaches is a worrisome sign of not only the attackers' capabilities, but also their motives. These weren't opportunistic cybercriminals indiscriminately probing whatever targets they could find in hopes of extorting their victims for a quick payday. These were highly motivated attackers who selected each of their victims for a specific purpose that remains unknown.

"If you compromise somebody's network for 6 months, there's a lot of opportunity," said James Lewis, a cybersecurity expert at the Center for Strategic and International Studies, a security think tank. "It's an amazing coup for the Russians — really impressive."

An unusual and creative hack


A third reason for concern is the unusual and creative way the attackers carried out their operation: By disguising the initial attack within legitimate software updates issued by SolarWinds.

"SolarWinds is one of the most widely used and effective tools for network monitoring, including across federal networks and major corporations," said Jamie Barnett, a retired Navy rear admiral and senior vice president at the cybersecurity firm RigNet. "It takes a state-level cyberattack to get into the

SolarWinds updates and patches."

By piggybacking on otherwise trusted software updates, the attackers cleverly took advantage of the normal and recommended best practice of keeping software up to date. Thousands of companies and government agencies could thus have been exposed simply for doing the right thing.

That's what's so scary: It's not clear what could have been done differently in this case, because the very process meant to reassure users that "this software can be trusted" was itself compromised.

Once inside a target, the attackers waited patiently until they collected enough data on authorized users to impersonate them, allowing the hackers to move through a victim's network undetected for months, according to an analysis by the cybersecurity firm CrowdStrike.

The degree of access the hackers enjoyed, as well as the length of time they were able to collect information, may wind up making this "a much worse cyberattack than the Office of Personnel Management breach" disclosed by the US government in 2015, said Barnett. That breach, attributed to Chinese-linked hackers, resulted in the theft of vast troves of personal data on millions of federal employees and security clearance applicants.

The rising frequency and intensity of state-sponsored hacking has some security cybersecurity leaders reiterating calls for a global treaty on cyberwarfare.

"We need a set of binding rules," Microsoft president Brad Smith said at an event Tuesday held by the Ronald Reagan Foundation and Institute. "And we need a commitment by the democracies of the world to hold authoritarian regimes accountable, so they keep their hands off of civilians in this time of peace when it comes to cyberspace."

Other experts are increasingly questioning the reliance of many businesses on just a handful of third-party vendors, and saying that perhaps society makes it a little too easy for data to be accessed or shared, particularly during a pandemic when working remotely is normal for countless individuals.

"It begs the question: 'In cybersecurity, do we have a 'too big to fail' situation? And did it happen right under our noses, while we were telling everybody to spend more, to tool up, to get products?" said Payton.

Comments

Oh ya 5 year ago
And you think your online banking is safe LOL and i hope you Bitcoin owners dont start crying like little school girls when you wake up broke some morning

Newsletter

Related Articles

0:00
0:00
Close
UK’s Top Prosecutor Says ‘No One Is Above the Law’ as Police Review Claims Against Ex-Prince Andrew
Businessman Adam Brooks weighs in on the reports that the US is set to help Hamit Coskun flee the UK, over free speech concerns
U.S. Attorney General Pam Bondi Releases 3.5 Million Pages of Jeffrey Epstein Case Files
US Secretary of State Marco Rubio Comment on European allies report blaming Russia for killing late Kremlin critic Alexei Navalny using toxin from poison dart frogs
Eighty-Year-Old Lottery Winner Sentenced to 16.5 Years for Drug Trafficking
UK Quran Burner May Receive Asylum in the US Amid Legal Challenges
Rubio Calls for Sweeping U.N. Reform, Saying It Has Failed to End Wars in Gaza and Ukraine
10,000 Condoms Distributed at Winter Olympics 2026 Athlete Village Depleted Within 72 Hours
Poland's President Advocates for Evaluating Independent Nuclear Weapons Development
Prince William Meets Saudi Crown Prince as Epstein-Andrew Fallout Casts Shadow
Starmer Calls for Renewed ‘Hard Power’ Investment at European Security Summit
UK Police Establish National Taskforce to Handle Domestic Epstein-Linked Allegations
UK Court Rules Ban on Palestine Action Unlawful in Major Free Speech Test
UK Faces Prospect of Net Migration Turning Negative as Economic Impact Looms
Mayor of Serdobsk in Russia’s Penza Region Resigns After Housing Certificates Granted to Migrant Family Trigger Public Outcry
Pentagon Reviews Anthropic Partnership After Claude AI Reportedly Used in Operation Targeting Nicolás Maduro
President Donald Trump and Hip-Hop’s Political Realignment: Pardons, Public Endorsements, and the Struggle Over Cultural Influence
China’s EV Makers Face Mandatory Return to Physical Buttons and Door Handles in Driver-Distraction Safety Overhaul
Goldman Sachs and DP World Executive Resignations: Elite-Reputation Risk and Corporate Governance Fallout From the Epstein Disclosures
‘Amelia’: The UK Government’s Anti-Extremism Game Villain Who Became a Protest Symbol
Peter Mandelson Asked to Testify Before US Congress Over Jeffrey Epstein Links
Walmart's Earnings and UK Economic Data Highlight Upcoming Financial Trends
UK Green Party Considering Proposal to Legalize Heroin for an Inclusive Society
SpaceX's New Vision: Lunar City Takes Precedence Over Mars Colonization
OpenAI and DeepCent Superintelligence Race: Artificial General Intelligence and AI Agents as a National Security Arms Race
Document Suggests Prince Andrew Shared UK Briefing on Afghan Investment Opportunities with Jeffrey Epstein
We will protect them from the digital Wild West.’ Another country will ban social media for under-16s
McDonald's Shortens Breakfast Hours in Australia Due to Egg Shortage
Heineken announces cut of 6,000 jobs due to declining beer demand
Beijing Brands UK Hong Kong Visa Expansion ‘Despicable and Reprehensible’ After Jimmy Lai Sentencing
Tesco Chief Warns UK Is ‘Sleepwalking’ Toward a Joblessness Crisis
Trump’s ‘Act of Great Stupidity’ Comment on UK Chagos Deal Reverberates Through Diplomacy and Strategy
New U.S. filings say Jeffrey Epstein repaid Les Wexner one hundred million dollars after theft allegation
Commerce Secretary Howard Lutnick acknowledges 2012 visit to Jeffrey Epstein’s private island as lawmakers scrutinise past ties
Helsing and Stark Defence loitering-munition drones and Germany’s race to industrialise battlefield autonomy
UK orders deletion of Courtsdesk court-data archive, reigniting the fight over who controls public justice records
UK Police Review Fresh Claims Involving Prince Andrew as Senior Royals Respond to Epstein Files
Keir Starmer’s Premiership Faces Unprecedented Strain as Epstein Fallout Deepens
Starmer Vows to Stay in Office as UK Government Faces Turmoil After Epstein Fallout
China and UK Signal Tentative Reset with Commitment to Steadier, Professionally Managed Relations
UK Confirms Imminent Increase in ETA Fee to £20 as Entry Rules Tighten
UK Signals Possible Seizure of Russia-Linked ‘Shadow Fleet’ Tanker in Escalation of Sanctions Enforcement
Epstein Scandal Piles Unprecedented Pressure on UK Prime Minister Keir Starmer’s Leadership
UK’s ‘Most Romantic Village’ Celebrates Valentine’s Day and Explores the Festival’s Rich History
The Implications of Expanding Voting Rights to Non-EU Foreign Residents in France
Ghislaine Maxwell to Testify Before US Congress on February 9
Al.com Acquired by Crypto.com Founder for $70 Million
Apple iPhone Lockdown Mode blocks FBI data access in journalist device seizure
Belgium: Man Charged with Rape After Faking Payment to Sex Worker
KPMG Urges Auditor to Relay AI Cost Savings
×