Sign Up
..... Australian Property Network. It's All About Property!
Categories

Posted: 2024-01-20 02:29:18

State-backed Russian hackers broke into Microsoft's corporate email system and accessed the accounts of some of its leadership team, as well as some employees on its cybersecurity and legal teams, the company said on Friday.

In a blog post, Microsoft said the intrusion began in late November 2023 and was discovered on January 12. It said the same highly skilled Russian hacking team behind the 2020 SolarWinds breach was responsible.

"A very small percentage" of Microsoft corporate accounts were accessed, the company said, and some emails and attached documents were stolen.

A company spokesperson said Microsoft had no immediate comment on which or how many members of its senior leadership had their email accounts breached, but was in the process of notifying any affected employees.

In a regulatory filing on Friday, Microsoft said it was able to remove the hackers's access from the compromised accounts on or about January 13.

In a blog post, the company said the hackers were from a unit which Microsoft calls Midnight Blizzard. The group is also known as APT29, Nobelium or Cozy Bear by cybersecurity researchers and linked to Russia's SVR spy agency, according to US officials.

A security surveillance camera is seen near the Microsoft office building in Beijing.

Microsoft says the hackers used a "password spraying" attack and were able to log in to a "legacy" test account.(AP: Andy Wong)

"This attack does highlight the continued risk posed to all organisations from well-resourced nation-state threat actors like Midnight Blizzard," Microsoft said, noting that the attack was not the result of a specific vulnerability in its products or services.

"To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."

Hackers used 'password spraying' technique

Microsoft said the hackers were able to gain access by compromising credentials on a "legacy" test account, suggesting it had outdated code. After gaining a foothold, they used the account's permissions to access the accounts of the senior leadership team and others.

The brute-force attack technique used by the hackers is called "password spraying", in which a threat actor uses a simple or often-used password to try to log into multiple accounts.

View More
  • 0 Comment(s)
Captcha Challenge
Reload Image
Type in the verification code above