Illegal: The SolarWinds Hack under International Law.

In late 2020, news surfaced about one of the most extensive attacks on an information technology (IT) supply chain to date. Hackers exploited a vulnerability in the update system of Orion, a network-monitoring and management software developed by the company SolarWinds. Malicious code embedded in Or...

Descripción completa

Detalles Bibliográficos
Publicado en:European Journal of International Law Vol. 33; no. 4; pp. 1275 - 1287
Autores principales: Coco, Antonio, Dias, Talita, van Benthem, Tsvetelina
Formato: Artículo
Publicado: Oxford University Press / USA Nov2022
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:In late 2020, news surfaced about one of the most extensive attacks on an information technology (IT) supply chain to date. Hackers exploited a vulnerability in the update system of Orion, a network-monitoring and management software developed by the company SolarWinds. Malicious code embedded in Orion updates created a backdoor into the systems used by numerous private and public entities. This backdoor was then used to insert additional malware into affected systems – in particular, spyware to exfiltrate confidential or sensitive data. Considering both the importance of preserving the integrity of IT supply chains and the diverse risks of harm that attacks such as the SolarWinds hack give rise to, this article examines this cyber operation according to the relevant rules of international law – notably those on sovereignty, non-intervention, general due diligence duties and international human rights law. It concludes that the operation may have been illegal on multiple fronts.