Skip to main content

Microsoft Employee Emails Hacked by Russia-Linked 'Midnight Blizzard' Group, Company Says

Microsoft said a Russian-linked hacking group attacked its corporate systems, getting into a “small number” of email accounts, including those of senior leadership and employees who work in cybersecurity and legal. The company said it's acting immediately to fix older systems, which will probably cause some disruption.

The hacking group doesn't appear to have accessed customers' systems or Microsoft servers that run outward-facing products, the software giant said Friday in a blog post. Microsoft also has no evidence the group, named Midnight Blizzard, got into source code or artificial intelligence systems.

“We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes, even when these changes might cause disruption to existing business processes,” the company said. “This will likely cause some level of disruption.”

The group that Microsoft deemed responsible, also known as “Nobelium,” is a sophisticated nation-state hacking group that the US government has tied to Russia. The same group previously breached SolarWinds, a US federal contractor, as part of a massive cyber-espionage effort against US federal agencies.

The company said hackers beginning in November used a “password spray” attack to infiltrate its systems. That technique, sometimes known as a “brute force attack,” typically involves outsiders quickly trying multiple passwords on specific user names in order to try breaching targeted corporate accounts.

In this case, in addition to the accessed accounts, the attackers also took emails and attached documents. Microsoft said it detected the hack on January 12, adding that the company is still notifying employees whose emails were accessed.

Eric Goldstein, executive assistant director for cybersecurity at the US Cybersecurity and Infrastructure Security Agency, said government officials are “closely coordinating with Microsoft to gain additional insights into this incident and understand impacts so we can help protect other potential victims.”

Microsoft technology has frequently been the target of major hacking campaigns.

The US Cyber Safety Review Board, which reports to the Department of Homeland Security, is already assessing a 2023 intrusion against Microsoft Exchange Online that the company attributed to China-linked hackers. That breach enabled the hack of senior US officials' email accounts and has prompted growing concerns about cloud computing security. Microsoft said in September it identified five different errors in how its systems that have “been corrected.”

In an interview with Bloomberg in 2023 following that breach, Jen Easterly, director of the agency that manages the board, suggested that Microsoft should “recapture the ethos” of what Microsoft co-founder Bill Gates called “trustworthy computing” in 2002, when he instructed employees to focus on security over adding new features.

“I absolutely positively think they have to focus on ensuring their products are both secure by default and secure by design, and we are going to continue to work with them to urge them to do that,” Easterly said of Microsoft.

In November, Microsoft said it was overhauling how it protects its software and systems after a series of high-profile hacks. Now the company said it must pick up the pace on changes, particularly to older systems and products.

“For Microsoft, this incident has highlighted the urgent need to move even faster,” the company said Friday.

© 2024 Bloomberg LP


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.


from Gadgets 360 https://ift.tt/sKvmEec

Comments

Popular posts from this blog

Itel P55 With Dual Rear Cameras, 5,000mAh Battery Launched in India: Price, Specifications

Itel P55 5G was launched in India on Tuesday and it claims to be the cheapest 5G smartphone in the country. The phone is powered by an octa-core Dimensity chipset and supports wired fast charging. It carries an AI-powered dual rear camera unit and is offered in a single storage variant along with two colour options. Itel India also introduced the Itel S23+ alongside, and is a budget smartphone with a curved AMOLED display. The company is extending a two-year warranty on the handsets and is also offering free screen replacement within 100 days of purchase. Itel P55 5G price in India, availability Offered in Blue and Green colour options, the singular 8GB + 128GB variant of the Itel P55 5G is priced at Rs. 9,999. The phone will be available for purchase via Amazon India starting October 4. Itel P55 5G specifications, features Sporting a 6.6-inch HD+ (1600 x 700 pixels) display, the dual nano SIM-supported Itel P55 comes with a refresh rate of 90Hz. The phone is powered by an octa-co...

Redmi K60 Cooling Case Said to Reduce Maximum Temperature by 4 Degrees Celsius

Redmi K60 series was launched in China on Tuesday. This flagship lineup includes the Qualcomm Snapdragon 8 series-powered Redmi K60 and Redmi K60 Pro, and the Redmi K60E featuring a MediaTek Dimensity 8200 SoC. They are equipped with a 17-layer heat liquid cooling VC dissipation system that is said to offer up to 15 percent improved thermal conductivity than the previous generation. Xiaomi has also released a cooling case for the Redmi K60 series which is supposedly capable of further reducing the maximum temperature by up to 4 degrees Celsius. According to a post by a digital blogger on Weibo, the Redmi K60 Series Ice Cooling Case can reduce the handset's maximum temperature by up to 4 degrees Celsius. This case is available to purchase for CNY 79 (roughly Rs. 1,000). Xiaomi says that this cooling case is equipped with a phase-changing material that purportedly switches between solid and liquid states depending on the smartphone's temperature to dissipate heat efficiently....

Samsung Galaxy S24 Series Could Come With Exynos SoC in Europe, Galaxy S24 Ultra Storage Options Tipped

Samsung will reportedly launch the successor to the Galaxy S23 series early next year. While the smartphones are still months away from their debut, several rumours and leaks have revealed expected specifications and features of the purported Galaxy S24 series. The Galaxy S24 series will likely comprise a Galaxy S24, Galaxy S24+, and a Galaxy S24 Ultra. Now, details of the phones' processor and their storage options has been leaked online. The phones are tipped to get an Exynos processor in Europe. A new leak by tipster Ice Universe (@UniverseIce) revealed that the Galaxy S24 series will ship in Europe with the Exynos 2400 SoC with cores clocked at a speed of 3.16GHz, 2.9GHz, 2.6GHz, and 1.95GHz. Additionally, the tipster went on to reveal some more details about the purported smartphones. The Galaxy S24+ is said to come with a WQHD+ screen with 3120x1440 resolution whereas all three models will offer a peak brightness of 2,500 nits. The tipster has also teased the renders of...