Cyber Attacks

Russian hackers accessed Microsoft corporate emails

0

Microsoft warned that some of its corporate email accounts were breached and data were stolen by a Russian state-sponsored hacking group known as Midnight Blizzard.

Microsoft detected the attack on January 12th and upon investigation it was determined that the attack was conducted by Russian threat actors known more commonly as Nobelium or APT29.

The hackers breached the systems in November 2023 when they conducted a password spray attack to access a legacy non-production test tenant account.

A password spray is a type of brute force attack where threat actors collect a list of potential login names and then attempt to log in to all of them using a particular password. If that password fails, they repeat this process with other passwords until they run out or successfully breach the account.

As the hackers were able to gain access to the account using a brute force attack, it indicates that it was not protected with two-factor authentication (2FA) or multi-factor authentication (MFA).

Once the hackers gained access to the “test” account, they used it to access a “small percentage” of Microsoft’s corporate email accounts for over a month.

The breached email accounts included members of Microsoft’s leadership team and employees in the cybersecurity and legal departments, from which the hackers stole emails and attachments.

According to the Microsoft Security Response Center, the investigation indicates they were initially targeting email accounts for information related to Midnight Blizzard itself.

The tech giant, however, did not disclose how many email accounts were infiltrated, and what information was accessed, and is in the process of notifying employees whose email was accessed.

Microsoft repeats that this breach was not caused by a vulnerability in their products and services but rather by a brute force password attack on their accounts.

However, based on the limited information shared by Microsoft, it appears that a big part of the breach was caused by the poorly secured configuration of the breached account.

The company assures that the breach has not had a material impact on the company’s operations.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Russian ColdRiver hackers release custom malware

Previous article

Apache ActiveMQ flaw exploited in the Godzilla Web Shell attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *