Russian hackers stole Microsoft corporate emails in month-long breach
Microsoft has disclosed that several of its corporate email accounts were breached by a Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12, 2024. Microsoft’s internal investigation concluded that the attack was conducted by a group of Russian threat actors associated with Nobelium/APT29 (sometimes known as Midnight Blizzard or Cozy Bear). The software titan said that the threat actors breached their systems in November 2023 by conducting a password spray attack to access a legacy non-production test tenant account. Microsoft says the hackers accessed a “small percentage” of Microsoft’s corporate email accounts for over a month including accounts tied to the company’s leadership team and employees in the cybersecurity and legal departments. The company speculates that the threat actors were looking for information about their own gang.
The fact that the hackers were able to gain access to the account using a brute force attack indicates it was not protected with two-factor authentication (2FA) or multi-factor authentication (MFA), a security practice that Microsoft recommends on all types of online accounts.
How It Could Affect Your Business: Even the biggest companies can be brought low by a simple cybersecurity problem.
I Do I.T. to the Rescue: An endpoint detection and response solution can help businesses stop the spread of a cyberattack fast.
Get In Touch
Share On Social Media
Other Recent Blog Articles
The Critical Role of IT in HIPAA Compliance: A Guide for Portland Healthcare
Healthcare providers and their business associates face one of the most significant regulatory challenges today: HIPAA Compliance. It’s more than just paperwork; it’s a rigorous, ongoing commitment to safeguarding patient…
Read MoreNavigating the Cloud Storm: Lessons from the Recent AWS Outage for Portland Small Businesses
Even the giants of the tech world experience turbulence. The recent AWS outage, which impacted countless online services and businesses globally, serves as a stark reminder: no single cloud provider…
Read MoreThe Latest Supply Chain Breach: Why Proactive IT Managed Services is Essential
Every week brings news of another massive corporate cyberattack. While the headlines focus on multinational giants—like the recent, disruptive Supply Chain Attack that leveraged a vulnerability in third-party software—the underlying…
Read More