CISA Issues Emergency Order On Microsoft Breach By Russian Hackers

Affected bodies must take immediate action, agency says

clock • 2 min read
CISA Issues Emergency Order On Microsoft Breach By Russian Hackers

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) published its recently issued emergency directive on Thursday, which confirmed that a Russian state-sponsored hacker group was able to steal emails from federal agencies in connection with the breach of Microsoft executive accounts.

The threat actor, known as Midnight Blizzard, has been associated with Russia's SVR foreign intelligence unit by the US government.

Through the compromise of Microsoft corporate email accounts, Midnight Blizzard has "exfiltrated email correspondence between Federal Civilian Executive Branch (FCEB) agencies and Microsoft," CISA said in the emergency directive.

"The threat actor is using information initially exfiltrated from the corporate email systems, including authentication details shared between Microsoft customers and Microsoft by email, to gain, or attempt to gain, additional access to Microsoft customer systems," CISA said in the directive.

The emergency directive orders federal agencies to "immediately mitigate" the "significant risk" posed by the threat actor, including through analyzing the content of stolen emails and resetting credentials.

The breach was first disclosed by Microsoft in January and is believed to have begun in November. The compromise was initially believed to have affected members of the tech giant's senior leadership team as well as employees on its cybersecurity and legal teams.

In an update on the incident in early March, Microsoft disclosed that Midnight Blizzard had been observed continuing to seek to exploit information gathered in the attack. The threat group has previously been held responsible for attacks including the widely felt 2020 breach of SolarWinds.

‘Immediate Action'

The emergency directive is dated 2nd April and was previously confirmed by Microsoft in a statement to CRN. The existence of the directive was first reported by Scoop News Group.

The directive "requires immediate action by agencies to reduce risk to our federal systems," CISA director Jen Easterly said in a news release.

"For several years, the US government has documented malicious cyber activity as a standard part of the Russian playbook," Easterly said. "This latest compromise of Microsoft adds to their long list."

The directive follows the recent blistering report about Microsoft's security culture and practices issued by the US Homeland Security-appointed Cyber Safety Review Board.

Earlier this month, the board released a 34-page report on last year's Microsoft Exchange Online breach, which was linked to China and impacted multiple federal agencies and officials including Commerce Secretary Gina Raimondo. The review board pinned the cloud email breach on a "cascade of Microsoft's avoidable errors."

In the Midnight Blizzard attack, meanwhile, Microsoft confirmed in late January that hackers initially gained access by exploiting a lack of multifactor authentication on a "legacy" account.

This article first appeared on CRN

 

You may also like
Midmarket Reacts, Recovers From CrowdStrike Outage

Software

Needless to say, the outage placed additional burden on IT departments, particularly those in the midmarket where budgets and team sizes can be limited.

clock 07-23-2024 • 5 min read
SolarWinds Patches Eight Critical Flaws In Access Rights Manager Software

Security

The latest revelation comes as a U.S. district judge last week dismissed most of a lawsuit that accused SolarWinds of misleading investors.

clock 07-22-2024 • 3 min read
Access Point: Weekly News Roundup For IT Executives – July 19, 2024

Column

Access Point is a weekly roundup of major tech news for IT executives on the go. This edition covers July 15-July 19.

clock 07-19-2024 • 1 min read

More on Security

SolarWinds Patches Eight Critical Flaws In Access Rights Manager Software

SolarWinds Patches Eight Critical Flaws In Access Rights Manager Software

The latest revelation comes as a U.S. district judge last week dismissed most of a lawsuit that accused SolarWinds of misleading investors.

clock 07-22-2024 • 3 min read
Protect AI Releases 'Bug Bounty' Report On July Vulnerabilities

Protect AI Releases 'Bug Bounty' Report On July Vulnerabilities

The vulnerabilities involve tools used to build machine language models that fuel artificial intelligence applications.

Samara Lynn
clock 07-18-2024 • 3 min read
Kaspersky Exiting US Market After Ban: What To Know If You're Running Its Software

Kaspersky Exiting US Market After Ban: What To Know If You're Running Its Software

Experts offer guidance for midmarket IT leaders on navigating their organizations through the government's Kaspersky ban and the company's move to shutter its U.S. operations.

Samara Lynn
clock 07-18-2024 • 8 min read