The SolarWinds supply chain attack was a highly sophisticated identity-based attack executed via a "backdoor" into a SolarWinds update server. The attackers bypassed multi-factor authentication and moved laterally within the network, posing as regular users. Information stolen from those systems and malware left behind by the hackers will likely be used for follow-on attacks, including account takeover. No single security solution could have prevented this attack, but using identity and password security could have helped. The timeline of the attack includes Compromise, Distribution, and Aftermath phases. The attack's full extent is still unknown, and witness testimonies provided critical insights.