U.S. Warns Agencies of Possible Breach via Microsoft Hack

Agencies were urged to reset credentials and secure cloud accounts.

Bloomberg News

April 11, 2024

2 Min Read
laptop with microsoft logo on the screen
Bloomberg

(Bloomberg) -- US federal agencies were ordered to analyze emails, reset compromised credentials and work to secure Microsoft Corp. cloud accounts amid concerns that a Russian nation-state hacking group may have accessed some correspondence.

The directive from the US Cybersecurity and Infrastructure Security Agency, known as CISA, came in response to breach of Microsoft that the tech giant disclosed in January. A Russian state-sponsored group called Midnight Blizzard was accused of exfiltrating data from Microsoft and using it to try compromise some of the company’s customers, according to the CISA alert. That includes correspondence between federal agencies and Microsoft, according to CISA.

The emergency directive was initially issued on April 2 and made public Thursday.

Microsoft and CISA have notified all federal agencies whose emails may have been compromised by the hacking group, according to the government directive. It didn’t disclose the names or number of agencies.

The incident represents a “grave and unacceptable risk” to agencies, according to the directive.

A spokesperson for the Russian Embassy in Washington didn’t immediately respond to a request for comment.

Asked if the hacking campaign had been stopped, Eric Goldstein, executive assistant director at CISA, said the group poses a “persistent threat to organizations public and private.”

Related:Feds to Microsoft: Clean Up Your Cloud Security Act Now

Federal agencies have until April 30 to reset credentials for related applications, and are also required to identify affected email correspondence by that deadline as well.

In January, Microsoft said it had been warning organizations that they were targets of the same Russian-sponsored group that hacked into sensitive corporate email accounts last year. The hackers — also known as Cozy Bear — have been identified by Microsoft’s threat intelligence team as the same cyber-espionage group that “has been targeting other organizations,” according to the January blog post.

Hewlett Packard Enterprise Co. also reported in January that it suffered a breach of its cloud-based email system that it said was likely caused by Midnight Blizzard.

The new US directive was previously reported by security news site CyberScoop.

About the Author

Bloomberg News

The latest technology news from Bloomberg.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like