Skip to main content

Microsoft Employee Emails Hacked by Russia-Linked 'Midnight Blizzard' Group, Company Says

Microsoft said a Russian-linked hacking group attacked its corporate systems, getting into a “small number” of email accounts, including those of senior leadership and employees who work in cybersecurity and legal. The company said it's acting immediately to fix older systems, which will probably cause some disruption.

The hacking group doesn't appear to have accessed customers' systems or Microsoft servers that run outward-facing products, the software giant said Friday in a blog post. Microsoft also has no evidence the group, named Midnight Blizzard, got into source code or artificial intelligence systems.

“We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes, even when these changes might cause disruption to existing business processes,” the company said. “This will likely cause some level of disruption.”

The group that Microsoft deemed responsible, also known as “Nobelium,” is a sophisticated nation-state hacking group that the US government has tied to Russia. The same group previously breached SolarWinds, a US federal contractor, as part of a massive cyber-espionage effort against US federal agencies.

The company said hackers beginning in November used a “password spray” attack to infiltrate its systems. That technique, sometimes known as a “brute force attack,” typically involves outsiders quickly trying multiple passwords on specific user names in order to try breaching targeted corporate accounts.

In this case, in addition to the accessed accounts, the attackers also took emails and attached documents. Microsoft said it detected the hack on January 12, adding that the company is still notifying employees whose emails were accessed.

Eric Goldstein, executive assistant director for cybersecurity at the US Cybersecurity and Infrastructure Security Agency, said government officials are “closely coordinating with Microsoft to gain additional insights into this incident and understand impacts so we can help protect other potential victims.”

Microsoft technology has frequently been the target of major hacking campaigns.

The US Cyber Safety Review Board, which reports to the Department of Homeland Security, is already assessing a 2023 intrusion against Microsoft Exchange Online that the company attributed to China-linked hackers. That breach enabled the hack of senior US officials' email accounts and has prompted growing concerns about cloud computing security. Microsoft said in September it identified five different errors in how its systems that have “been corrected.”

In an interview with Bloomberg in 2023 following that breach, Jen Easterly, director of the agency that manages the board, suggested that Microsoft should “recapture the ethos” of what Microsoft co-founder Bill Gates called “trustworthy computing” in 2002, when he instructed employees to focus on security over adding new features.

“I absolutely positively think they have to focus on ensuring their products are both secure by default and secure by design, and we are going to continue to work with them to urge them to do that,” Easterly said of Microsoft.

In November, Microsoft said it was overhauling how it protects its software and systems after a series of high-profile hacks. Now the company said it must pick up the pace on changes, particularly to older systems and products.

“For Microsoft, this incident has highlighted the urgent need to move even faster,” the company said Friday.

© 2024 Bloomberg LP


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.


from Gadgets 360 https://ift.tt/sKvmEec

Comments

Popular posts from this blog

Samsung Galaxy S24 Series Pre-Order Details Leak Out; Galaxy S24+ Spotted on Walmart Listing

Samsung Galaxy S24 series is expected to be unveiled on January 17 and past rumours have already given us a fair idea of what to expect from the new flagship phones. The most recent leaks suggest video recording upgrades on the Samsung Galaxy S24, Galaxy S24+, and Galaxy S24 Ultra along with some pre-order perks. The regular models are also tipped to be priced lower than their predecessors. The Galaxy S24 Ultra, in contrast, could see a price jump across all three storage variants. Meanwhile, Walmart accidentally listed the Galaxy S24+ on its online website, whereas Samsung retailers in Brazil have also started teasing the phone ahead of the debut. On X (formerly Twitter), Tipster Ice Universe (@UniverseIce)  posted that Samsung's flagship Galaxy S24 phones will be priced slightly lower than expected. He claimed that Galaxy S24 and Galaxy S24+ stock is large this time as the company is optimistic about the upcoming phones. Further, the Galaxy S24 series is said to offer the abili

End-of-Season Savings on Convertible Air Conditioners Starting at Rs. 22,990

Check out Croma's latest deals on Convertible Air Conditioners, with prices starting from just Rs. 22,990. This sale brings together top brands like Voltas, Daikin, and Croma, offering a mix of high-tech features and value for money. Whether you're looking for energy-saving options or models with the latest cooling technology, there's something for everyone. Plus, these ACs are more environmentally friendly. Big discounts on the usual prices and special bank offers make this a great time to upgrade your air conditioner. Croma 4 in 1 Convertible 1.5 Ton 3 Star Inverter Split AC Get the Croma 4 in 1 Convertible AC at a great deal of Rs. 28,990, down from Rs. 42,000. Made for compact spaces, this 3-star, 1.5 Ton AC is efficient and eco-friendly, complete with a PM 2.5 filter. HDFC Bank users can avail themselves of an extra discount, making it an even better bargain. Buy now at: Rs. 28,990 (MRP Rs. 42,000) Voltas 183V Vectra Platina 4 in 1 Convertible 1.5 Ton 3 Star Invert

Google Pixel Watch 2 Spotted on Google Play Console; Specifications, Chipset Tipped

Google Pixel Watch 2 is expected to launch soon as the successor to the Google Pixel Watch , which was released in October 2022. The debut Pixel Watch model has a 1.2-inch AMOLED touch display protected by 3D Corning Gorilla Glass 5 and an Exynos 9110 SoC. The watch also claimed to have a battery life of up to 24 hours. However, the upcoming Pixel Watch 2 is expected to include an improved SoC and battery. There have been several rumours about the purported smartwatch. The wearable was reportedly spotted on Google Play Console, where some key specifications were listed. A 9to5Google report says that the Pixel Watch 2 was recently spotted on the Google Play Console. The listing shows some key details of the smart wearable, including its processor, display and software specifications. The report says that the watch is likely to be powered by a Qualcomm SW5100 SoC, which claims to be the Snapdragon W5 chipset, not the W5+ variant. It is also tipped to retain 2GB of RAM from the precedi