Microsoft executive emails hacked by Russian intelligence group

0

[ad_1]

Satya Nadella, CEO of Microsoft.

CNBC

Microsoft said in a Friday regulatory filing that a Russian intelligence group accessed some of the software maker’s top executives’ email accounts. Nobelium, the same group that breached government supplier SolarWinds in 2020, carried out the attack, which Microsoft detected last week, according to the company.

It isn’t the first time Russian hackers have gained entry into Microsoft’s systems. State-sponsored attacks that can result in the dissemination of sensitive data becomes a greater risk during periods of armed conflict, and Russia’s war against Ukraine has been going on for almost two years now. On Thursday, Russia said Ukrainian forces conducted drone strikes in multiple Russian locations.

Microsoft’s announcement comes after new U.S. requirements for disclosing cybersecurity incidents went into effect. A Microsoft spokesperson said that while the company does not believe the attack had a material effect, it still wanted to honor the spirit of the rules.

The Cybersecurity and Infrastructure Security Agency is “closely coordinating with Microsoft to gain additional insights into this incident and understand impacts so we can help protect other potential victims,” CISA executive assistant director for cybersecurity Eric Goldstein said in a statement to CNBC. “As noted in Microsoft’s announcement, at this time we are not aware of impacts to Microsoft customer environments or products.” 

In late November, the group accessed “a legacy non-production test tenant account,” Microsoft’s Security Response Center wrote in the blog post. After gaining access, the group “then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents,” the corporate unit wrote.

The company’s senior leadership team, including Chief Financial Offer Amy Hood and President Brad Smith, regularly meets with CEO Satya Nadella.

Microsoft said it has not found signs that Nobelium had accessed customer data, production systems or proprietary source code.

The U.S. government and Microsoft consider Nobelium to be part of the Russian foreign intelligence service SVR. The hacking group was responsible for one of the most prolific breaches in U.S. history when it added malicious code to updates to SolarWinds’ Orion software, which some U.S. government agencies were using. Microsoft itself was ensnared in the hack.

Nobelium, also known as APT29 or Cozy Bear, is a sophisticated hacking group that has attempted to breach the systems of U.S. allies and the Department of Defense. Microsoft also uses the name Midnight Blizzard to identify Nobelium.

It was also implicated alongside another Russian hacking group in the 2016 breach of the Democratic National Committee’s systems.

Last year, a vulnerability in Microsoft software allowed China-aligned hackers to access the email accounts of senior government officials, including Commerce Secretary Gina Raimondo, ahead of a critical U.S.-China meeting. The company’s “negligent cybersecurity practices” led to the attack, Sen. Ron Wyden, a Democrat from Oregon, wrote in a letter to CISA director Jen Easterly, and other federal officials.

“We are continuing our investigation and will take additional actions based on the outcomes of this investigation and will continue working with law enforcement and appropriate regulators,” the Microsoft blog post said.

The Federal Bureau of Investigation told CNBC that it knows about the attack and is working with federal partners to help.

Don’t miss these stories from CNBC PRO:

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 81,029.00
ethereum
Ethereum (ETH) $ 2,500.92
tether
Tether (USDT) $ 0.999932
bnb
BNB (BNB) $ 720.37
xrp
XRP (XRP) $ 1.45
usd-coin
USDC (USDC) $ 0.999922
solana
Solana (SOL) $ 104.89
tron
TRON (TRX) $ 0.331731
staked-ether
Lido Staked Ether (STETH) $ 2,265.05
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
hyperliquid
Hyperliquid (HYPE) $ 84.01
zcash
Zcash (ZEC) $ 947.32
dogecoin
Dogecoin (DOGE) $ 0.089047
rain
Rain (RAIN) $ 0.017159
monero
Monero (XMR) $ 520.29
usds
USDS (USDS) $ 1.00
wrapped-steth
Wrapped stETH (WSTETH) $ 2,779.67
chainlink
Chainlink (LINK) $ 11.73
whitebit
WhiteBIT Coin (WBT) $ 74.08
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 76,243.00
leo-token
LEO Token (LEO) $ 9.37
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 2,466.93
cardano
Cardano (ADA) $ 0.221732
stellar
Stellar (XLM) $ 0.186718
bitcoin-cash
Bitcoin Cash (BCH) $ 257.97
dai
Dai (DAI) $ 0.999902
wrapped-eeth
Wrapped eETH (WEETH) $ 2,465.31
canton-network
Canton (CC) $ 0.111345
ethena-usde
Ethena USDe (USDE) $ 0.999950
susds
sUSDS (SUSDS) $ 1.08
usd1-wlfi
USD1 (USD1) $ 0.999661
litecoin
Litecoin (LTC) $ 51.31
uniswap
Uniswap (UNI) $ 6.12
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 76,366.00
the-open-network
Gram (prev. Toncoin) (GRAM) $ 1.37
hedera-hashgraph
Hedera (HBAR) $ 0.079927
avalanche-2
Avalanche (AVAX) $ 7.50
weth
WETH (WETH) $ 2,268.37
global-dollar
Global Dollar (USDG) $ 1.00
sui
Sui (SUI) $ 0.787559
shiba-inu
Shiba Inu (SHIB) $ 0.000005
usdt0
USDT0 (USDT0) $ 0.998824
paypal-usd
PayPal USD (PYUSD) $ 1.00
crypto-com-chain
Cronos (CRO) $ 0.057384
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
tether-gold
Tether Gold (XAUT) $ 4,481.51
hashnote-usyc
Circle USYC (USYC) $ 1.14
near
NEAR Protocol (NEAR) $ 2.00
memecore
MemeCore (M) $ 1.07
Shares