---
title: Many SolarWinds Customers Failed to Secure Systems Following Hack
description: Security Week recently covered the recent report from RiskRecon detailing how organizations are reacting to the SolarWinds breach.
---

[Media Coverage | RiskRecon ](https://blog.riskrecon.com/company/media-coverage)

# [Many SolarWinds Customers Failed to Secure Systems Following Hack](https://blog.riskrecon.com/company/media-coverage/many-solarwinds-customers-failed-to-secure-systems-following-hack)

 Written by [Security Week](https://blog.riskrecon.com/company/media-coverage/author/security-week) | Feb 19, 2021 6:00:50 PM

**Many companies still expose SolarWinds Orion to the internet and have failed to take action following the disclosure of the [massive SolarWinds breach](https://www.securityweek.com/continuous-updates-everything-you-need-know-about-solarwinds-attack), according to RiskRecon, a Mastercard company that specializes in risk assessment.**

Threat actors believed to be backed by Russia breached Texas-based IT management firm SolarWinds and used that access to deliver a piece of malware named Sunburst to roughly 18,000 customers who had been using the company’s Orion monitoring product. A few hundred victims that presented an interest to the hackers received other payloads that provided deeper access into their environments.

A second, apparently unrelated threat group believed to be operating out of China also targeted SolarWinds, [delivering a piece of malware named Supernova](https://www.securityweek.com/china-linked-hackers-exploited-solarwinds-flaw-us-government-attack-report). The delivery of Supernova required access to the targeted network and involved exploitation of a zero-day vulnerability in Orion, which SolarWinds patched shortly after its existence came to light.

RiskRecon on Friday said it observed 1,785 organizations[ exposing Orion to the internet](https://blog.riskrecon.com/how-the-world-responded-to-solarwinds-orion-a-view-from-the-internet-part-1) on December 13, 2020, shortly after the breach came to light, and the number dropped to 1,330 by February 1, 2021. However, only 8% of these companies have applied the Orion update (2020.2.4) released by SolarWinds in response to the breach.

[View full post](https://blog.riskrecon.com/company/media-coverage/many-solarwinds-customers-failed-to-secure-systems-following-hack)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Security Week"
  },
  "dateModified" : "2021-02-19T18:00:50.746Z",
  "datePublished" : "2021-02-19T18:00:50Z",
  "headline" : "Many SolarWinds Customers Failed to Secure Systems Following Hack",
  "image" : {
    "@type" : "ImageObject",
    "height" : 256,
    "url" : "https://f.hubspotusercontent40.net/hubfs/2477095/security%20week%20logo.png",
    "width" : 256
  },
  "mainEntityOfPage" : "https://blog.riskrecon.com/company/media-coverage/many-solarwinds-customers-failed-to-secure-systems-following-hack",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "RiskRecon Media Coverage"
  }
}
```