iTnews Asia
  • Home
  • News
  • Security

US cyber agency says Russian hackers used Microsoft to access govt mails

US cyber agency says Russian hackers used Microsoft to access govt mails

Warns non-governmental groups and other organisations.

By Raphael Satter on Apr 12, 2024 9:38AM

The US Cybersecurity and Infrastructure Security Agency said Russian government-backed hackers have used their access to Microsoft's email system to steal correspondence between officials and the tech giant, an emergency directive by the US watchdog released on Thursday showed.

In the directive dated April 2, the agency warned that hackers were exploiting authentication details shared by email to try to break into Microsoft's customer systems, including those of an unspecified number of government agencies.

The warning that government agencies are being targeted using stolen Microsoft emails follows the company's announcement in March that it was still wrestling with the intruders, which it nicknames "Midnight Blizzard."

That disclosure, which set alarm bells ringing across the cybersecurity industry, was followed just last week by a report from the US Cyber Safety Review Board which said that a separate hack - blamed on China - had been preventable, faulting the company for cybersecurity lapses and a deliberate lack of transparency.

CISA declined to name agencies that might have been affected. Microsoft said in an email that it was "working with our customers to help them investigate and mitigate. This includes working with CISA on an emergency directive to provide guidance to government agencies."

The Russian Embassy in Washington, which in the past has denied being behind hacking campaigns, did not immediately return a message seeking comment.

CISA warned that the hackers might have gone after non-governmental groups as well.

"Other organisations may also have been impacted by the exfiltration of Microsoft corporate email," CISA said, encouraging customers to contact Microsoft for further details.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
microsoft security us cybersecurity and infrastructure security agency

Related Articles

  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
  • Cybersecurity threats CISOs should be most worried about in 2025
  • Ways to secure your inbox against the next wave of cyberattacks
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

How cybercriminals are exploiting LLMs to harm your business

How cybercriminals are exploiting LLMs to harm your business

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Is identity now the next parameter of cybersecurity breaches?

Is identity now the next parameter of cybersecurity breaches?

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.