Skip to main content

Microsoft Employee Emails Hacked by Russia-Linked 'Midnight Blizzard' Group, Company Says

Microsoft said a Russian-linked hacking group attacked its corporate systems, getting into a “small number” of email accounts, including those of senior leadership and employees who work in cybersecurity and legal. The company said it's acting immediately to fix older systems, which will probably cause some disruption.

The hacking group doesn't appear to have accessed customers' systems or Microsoft servers that run outward-facing products, the software giant said Friday in a blog post. Microsoft also has no evidence the group, named Midnight Blizzard, got into source code or artificial intelligence systems.

“We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes, even when these changes might cause disruption to existing business processes,” the company said. “This will likely cause some level of disruption.”

The group that Microsoft deemed responsible, also known as “Nobelium,” is a sophisticated nation-state hacking group that the US government has tied to Russia. The same group previously breached SolarWinds, a US federal contractor, as part of a massive cyber-espionage effort against US federal agencies.

The company said hackers beginning in November used a “password spray” attack to infiltrate its systems. That technique, sometimes known as a “brute force attack,” typically involves outsiders quickly trying multiple passwords on specific user names in order to try breaching targeted corporate accounts.

In this case, in addition to the accessed accounts, the attackers also took emails and attached documents. Microsoft said it detected the hack on January 12, adding that the company is still notifying employees whose emails were accessed.

Eric Goldstein, executive assistant director for cybersecurity at the US Cybersecurity and Infrastructure Security Agency, said government officials are “closely coordinating with Microsoft to gain additional insights into this incident and understand impacts so we can help protect other potential victims.”

Microsoft technology has frequently been the target of major hacking campaigns.

The US Cyber Safety Review Board, which reports to the Department of Homeland Security, is already assessing a 2023 intrusion against Microsoft Exchange Online that the company attributed to China-linked hackers. That breach enabled the hack of senior US officials' email accounts and has prompted growing concerns about cloud computing security. Microsoft said in September it identified five different errors in how its systems that have “been corrected.”

In an interview with Bloomberg in 2023 following that breach, Jen Easterly, director of the agency that manages the board, suggested that Microsoft should “recapture the ethos” of what Microsoft co-founder Bill Gates called “trustworthy computing” in 2002, when he instructed employees to focus on security over adding new features.

“I absolutely positively think they have to focus on ensuring their products are both secure by default and secure by design, and we are going to continue to work with them to urge them to do that,” Easterly said of Microsoft.

In November, Microsoft said it was overhauling how it protects its software and systems after a series of high-profile hacks. Now the company said it must pick up the pace on changes, particularly to older systems and products.

“For Microsoft, this incident has highlighted the urgent need to move even faster,” the company said Friday.

© 2024 Bloomberg LP


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.


from Gadgets 360 https://ift.tt/sKvmEec

Comments

Popular posts from this blog

Xiaomi Offers Free Xiaomi 12 Pro Upgrade to Mi 11 Ultra Users Facing Wi-Fi Issues

Xiaomi is offering a free upgrade to a Xiaomi 12 Pro for Mi 11 Ultra users who are facing Wi-Fi issues. These users also have the option to further upgrade to the company's latest Xiaomi 13 Pro by paying an extra fee of Rs. 30,000. Just recently, the company extended the warranty of the Mi 11 Ultra alongside other smartphones by two years, after users complained of camera and motherboard issues. The current offer — including the free upgrade and the paid one, is extended to the Mi 11 Ultra users who are having trouble with Wi-Fi on their handsets. The Xiaomi India President Muralikrishnan B announced the offers in a video message via Twitter. He added that the  Mi 11 Ultra users who had previously paid and upgraded their handsets to the Xiaomi 12 Pro will be offered a full refund. They will need to contact the company online or through the nearest Xiaomi service centre. Notably, this refund is only applicable to users who upgraded their handsets due to Wi-Fi issues....

Softbank CEO Says He is Heavy User of ChatGPT Speaks to OpenAIs Sam Altman Often

SoftBank Group 's Chief Executive Masayoshi Son said on Tuesday he is a "heavy user" of ChatGPT, the artificial intelligence-powered chatbot from Microsoft -backed startup OpenAI. Son said he is speaking "almost everyday" to OpenAI CEO Sam Altman , who has made high-profile visits to Tokyo this year as he looks to capitalise on interest in generative AI and exert influence on the regulation of the burgeoning technology around the world. "I am chatting with ChatGPT everyday - I am a heavy user," Son told shareholders of the group's telecoms subsidiary. Son has stepped back from public pronouncements in recent months to focus on the planned listing of chip designer Arm as his technology investment conglomerate books heavy loss due to the sliding value of its portfolio. The group holds its annual general meeting on Wednesday with the market looking for details of Son's investment outlook at a time when excitement over AI is driving capital...