{"id":522275,"date":"2024-01-20T08:26:46","date_gmt":"2024-01-20T06:26:46","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=522275"},"modified":"2024-01-20T08:32:22","modified_gmt":"2024-01-20T06:32:22","slug":"russian-hackers-breach-microsoft-systems","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/522275-russian-hackers-breach-microsoft-systems.html","title":{"rendered":"Russian hackers breach Microsoft systems"},"content":{"rendered":"<p>Microsoft Corp. said a Russian-linked hacking group attacked its corporate systems, getting into a \u201csmall number\u201d of email accounts, including those of senior leadership and employees who work in cybersecurity and legal.<\/p>\n<p>The company said it\u2019s acting immediately to fix older systems, which will probably cause some disruption.<\/p>\n<p>The hacking group doesn\u2019t appear to have accessed customers\u2019 systems or Microsoft servers that run outward-facing products, the software giant said Friday in a<strong>\u00a0<a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/01\/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard\/\" target=\"_blank\" rel=\"noopener noreferrer\">blog post<\/a><\/strong>.<\/p>\n<p>Microsoft also has no evidence the group, named Midnight Blizzard, got into source code or artificial intelligence systems.<\/p>\n<p>\u201cWe will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes, even when these changes might cause disruption to existing business processes,\u201d the company said. \u201cThis will likely cause some level of disruption.\u201d<\/p>\n<p>The group that Microsoft deemed responsible, also known as \u201cNobelium,\u201d is a sophisticated nation-state hacking group that the\u00a0<strong><a href=\"https:\/\/www.cisa.gov\/topics\/cyber-threats-and-advisories\/advanced-persistent-threats\/russia\" target=\"_blank\" rel=\"noopener noreferrer\">US government has tied<\/a>\u00a0<\/strong>to Russia.<\/p>\n<p>The same group previously breached SolarWinds Corp., a US federal contractor, as part of a\u00a0<strong><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-10-30\/solarwinds-misled-public-on-cyber-risk-before-hack-sec-claims\" target=\"_blank\" rel=\"noopener noreferrer\">massive cyber-espionage effort<\/a><\/strong>\u00a0against US federal agencies.<\/p>\n<p>The company said hackers beginning in November used a \u201cpassword spray\u201d attack to infiltrate its systems. That technique, sometimes known as a \u201cbrute force attack,\u201d typically involves outsiders quickly trying multiple passwords on specific user names in order to try breaching targeted corporate accounts.<\/p>\n<p>In this case, in addition to the accessed accounts, the attackers also took emails and attached documents. Microsoft said it detected the hack on Jan. 12, adding that the company is still notifying employees whose emails were accessed.<\/p>\n<p><a href=\"https:\/\/www.cisa.gov\/about\/leadership\/eric-goldstein\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Eric Goldstein<\/strong><\/a>, executive assistant director for cybersecurity at the US Cybersecurity and Infrastructure Security Agency, said government officials are \u201cclosely coordinating with Microsoft to gain additional insights into this incident and understand impacts so we can help protect other potential victims.\u201d<\/p>\n<p>Microsoft technology has frequently been the target of major hacking campaigns.<\/p>\n<p>The US Cyber Safety Review Board, which reports to the Department of Homeland Security, is already assessing a 2023 intrusion against Microsoft Exchange Online that the company attributed to China-linked hackers.<\/p>\n<p>That breach enabled the hack of senior US officials\u2019 email accounts and has prompted growing concerns about cloud computing security. Microsoft said in September it identified five different errors in how its systems that have \u201cbeen corrected.\u201d<\/p>\n<p>In an interview with Bloomberg in 2023 following that breach, Jen Easterly, director of the agency that manages the board, suggested that\u00a0<strong><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-08-11\/microsoft-s-role-in-email-breach-to-be-part-of-us-cyber-inquiry\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft should \u201crecapture the ethos<\/a><\/strong>\u201d of what Microsoft co-founder Bill Gates called \u201ctrustworthy computing\u201d in 2002, when he instructed employees to focus on security over adding new features.<\/p>\n<p>\u201cI absolutely positively think they have to focus on ensuring their products are both secure by default and secure by design, and we are going to continue to work with them to urge them to do that,\u201d Easterly said of Microsoft.<\/p>\n<p>In November, Microsoft said it was\u00a0<strong><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-11-02\/microsoft-vows-to-revamp-cyber-products-after-coming-under-fire\" target=\"_blank\" rel=\"noopener noreferrer\">overhauling how it protects its software<\/a><\/strong>\u00a0and systems after a series of high-profile hacks. Now the company said it must pick up the pace on changes, particularly to older systems and products.<\/p>\n<p>\u201cFor Microsoft, this incident has highlighted the urgent need to move even faster,\u201d the company said Friday.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The group that Microsoft deemed responsible, also known as \u201cNobelium,\u201d is a sophisticated nation-state hacking group that the\u00a0US government has tied\u00a0to Russia.<\/p>\n","protected":false},"author":341034,"featured_media":511218,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[72252,199,461,123,15533,43794],"class_list":["post-522275","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyberattacks","tag-hackers","tag-hacking","tag-microsoft","tag-russia","tag-russian-hackers"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/522275"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341034"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=522275"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/522275\/revisions"}],"predecessor-version":[{"id":522279,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/522275\/revisions\/522279"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/511218"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=522275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=522275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=522275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}