Microsoft Exchange Used to Hack Diplomats Before 2021 Breach

rpm

Admin
Staff member
Joined
Jul 22, 2003
Messages
66,806
Reaction score
5,057
Location
Johannesburg
Microsoft Exchange Used to Hack Diplomats Before 2021 Breach

Late last year, researchers at the Los Angeles-based cybersecurity company Resecurity stumbled across a massive trove of stolen data while investigating the hack of an Italian retailer.

Squirreled away on a cloud storage platform were five gigabytes of data that had been stolen during the previous three and half years from foreign ministries and energy companies by hacking their on-premises Microsoft Exchange servers. In all, Resecurity researchers found documents and emails from six foreign ministries and eight energy companies in the Middle East, Asia and Eastern Europe.
 
Microsoft quickly pinned the 2021 cyberattack on a group of Chinese state-sponsored hackers it named Hafnium, and the U.S., U.K., and their allies made a similar claim last month, attributing it to hackers affiliated with the Chinese government.
Microsoft is deflecting.
There is no proof that it was Chinese - anyone can rent a VM on Alibaba Cloud, Huawei Cloud, Tencent Cloud, Baidu AI Cloud (or AWS, GCP, Azure, Digital Ocean, Rackspace, etc) to mask the real identity.
All half decent hackers use a cloud server/hacked device connected to via vpn/tor.

I blame Microsoft for not securing Exchange properly.

Total number of vulnerabilities : 159

I blame Steve Ballmer "Developers, Developers, Developers" - it's quality, not quantity.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X