18.3 C
Auckland
Tuesday, April 30, 2024

Popular Now

Microsoft’s top leadership hacked

Microsoft hack news
Stock photo.

Members of the tech giant’s cybersecurity team were also affected in the breach.

Microsoft has claimed its corporate system was hit by a “nation-state” cyber attack allegedly launched by Russian-backed actors, saying the hack compromised the email accounts of “senior leadership” and employees across several sectors.

The company outlined the breach in a notice published on Friday, stating that a “Russian state-sponsored actor” dubbed “Midnight Blizzard” had gained access to multiple corporate email accounts beginning last November.

“The threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents,” the statement said.

Password spraying is a type of ‘brute force’ cyber attack in which a hacker attempts to use a single password to try and access many different user accounts. The method is used to avoid automatic lockouts that might occur with multiple login attempts, and is most effective on systems with lax security that allow default passwords or shared login credentials for several users.

Microsoft went on to say that the hackers apparently initially targeted its systems in search of information about “Midnight Blizzard” itself, but did not say what else they might have found in CEOs’ email boxes.

The company noted that there was no indication the attackers gained access to customer information, production systems or source code, and emphasized that the breach was “not the result of a vulnerability in Microsoft products or services.”

The tech giant has claimed to have been affected by several other “nation-state” cyber attacks in recent months, including a breach allegedly carried out by a “China-based threat actor” last summer. That hack was said to have accessed ten US government email accounts, including that of Commerce Secretary Gina Raimondo and some 60,000 messages between State Department staffers. In a blog post published at the time, Microsoft said the hackers had “espionage objectives,” but stated its conclusions were held with only “moderate confidence.”

Image credit: Unsplash+

Promoted Content

Source:RT News

No login required to comment. Name, email and web site fields are optional. Please keep comments respectful, civil and constructive. Moderation times can vary from a few minutes to a few hours. Comments may also be scanned periodically by Artificial Intelligence to eliminate trolls and spam.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest

Trending

Sport

Daily Life

Opinion

Wellington
scattered clouds
14.7 ° C
15.6 °
13.8 °
83 %
8.8kmh
40 %
Tue
15 °
Wed
16 °
Thu
12 °
Fri
12 °
Sat
13 °
-- Free Ads --spot_img