Russian state-sponsored hackers accessed the emails of Microsoft’s ‘senior leadership’

A hacking group linked to a Russian intelligence agency accessed the emails of several senior Microsoft executives and other employees, the company disclosed Friday.

Microsoft said it detected the attack on January 12, and has determined that a hacking group known as Midnight Blizzard or Nobelium is . That’s the same group behind the 2020 SolarWinds . Microsoft and US cybersecurity officials Nobelium is part of Russia’s Foreign Intelligence Service (SVR).

“Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents,” the company wrote in a blog post.

The company didn’t identify which members of its “senior leadership” were targeted, but said its initial suggests the group was looking for information related to itself. Company officials so far have no evidence that “customer environments, production systems, source , or AI systems,” were accessed.

Though the company says the attack “was not the result of a in Microsoft products or services,” it is taking steps to “immediately” the security of “Microsoft-owned legacy systems and internal .” The changes “will likely cause some level of ,” it added.

Source link