Microsoft Executives’ Emails Hacked by Group Tied to Russian Intelligence

Published: January 22, 2024

An elite hacking group sponsored by Russian intelligence gained entry to the emails of a few of Microsoft’s senior executives starting in late November, the corporate disclosed in a weblog put up and regulatory submitting on Friday.

Microsoft mentioned it had found the intrusion every week in the past and was nonetheless investigating. The hackers appeared to deal with combing by means of Microsoft’s company e mail accounts to search for data associated to the hacking group, which Microsoft’s researchers referred to as Midnight Blizzard.

The hackers appeared by means of emails from Microsoft’s senior management staff in addition to workers in cybersecurity, authorized and different teams, and took some emails and attachments, the corporate mentioned. The firm, which had labored with cybersecurity corporations and governments to research earlier assaults by the hacking group, didn’t title the executives whose emails had been focused.

The Russian Foreign Intelligence Service has run the hacking group since a minimum of 2008, in accordance to the U.S. Cybersecurity and Infrastructure Security Agency. The group is thought by quite a lot of nicknames, together with Cozy Bear, the Dukes and A.P.T. 29, and has been behind quite a few high-profile hacks, in response to earlier U.S. authorities investigations.

Targets have included the computer systems of the Democratic National Committee in 2015 and the tech provider SolarWinds, which allowed Russia to achieve entry to methods on the State Department, the Department of Homeland Security and components of the Pentagon in 2020. Microsoft referred to as that incident “the most sophisticated nation-state cyberattack in history.”

The methodology used within the new hack seems to be much less unique — a comparatively fundamental tactic often known as password spraying, by which hackers attempt widespread passwords on an enormous array of accounts. The group, which has been recognized to make use of this tactic, discovered a gap in an outdated account for a testing system, after which used that account’s permissions to achieve entry to the company e mail accounts, Microsoft mentioned.

“To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code or A.I. systems,” Microsoft mentioned in an announcement.

The regulatory submitting mentioned the corporate had notified and was working with legislation enforcement.

Microsoft, which provides expertise to many Western governments, has lengthy been the goal of nation-state hacking. Last 12 months, Chinese hackers breached Microsoft’s methods and gained entry to the e-mail accounts of Commerce Secretary Gina M. Raimondo and different authorities officers.

Source web site: www.nytimes.com