Microsoft Mitigates Hacker Access To Government Email Accounts


Microsoft announced that it recently blocked a group of hackers, which it labeled Storm-0558, that accessed email accounts belonging to around 25 organizations, including government agencies.

What Happened With Storm-0558

In a blog post, Microsoft said it began investigating abnormal activity in some email accounts on June 16 after being notified by customers.

Its investigation revealed that beginning May 15, the hacking group exploited a vulnerability to forge authentication tokens and gain entry into organizations’ Microsoft 365 accounts.

Using a compromised Microsoft consumer account signing key, the hackers could impersonate users and access email accounts through services like Outlook Web Access and Outlook.com.

Microsoft said Storm-0558 appears focused on espionage and data theft.

According to a recent joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, the federal agency observed suspicious activity in its Microsoft 365 logs.

This led to the discovery that advanced persistent threat actors had accessed and exfiltrated data from some Exchange Online Outlook accounts.

How The Issue Was Resolved

CISA and the FBI advised organizations using Exchange Online to implement enhanced monitoring and logging to detect similar attacks.

Their recommendations include enabling advanced audit logging features and gaining visibility into standard cloud traffic patterns.

Microsoft claims it has fully resolved the issue and blocked the hackers’ access. It is working with impacted customers and has notified them ahead of its public disclosure.

The company said it had found no evidence the hackers remained in any corporate systems.

Mitigating Future Cyberattacks

This latest activity comes as cyberattacks continue to increase against organizations worldwide.

United States Senator Mark R. Warner, Chairman of the Senate Select Committee on Intelligence, expressed concern over reports of the latest cyberattack and what would be needed to prevent future incidents.

“The Senate Intelligence Committee is closely monitoring what appears to be a significant cybersecurity breach by Chinese intelligence. It’s clear that the PRC is steadily improving its cyber collection capabilities directed against the U.S. and our allies. Close coordination between the U.S. government and the private sector will be critical to countering this threat.”

Microsoft plans to keep improving security around account keys and tokens to stay ahead of evolving cyber risks.

It emphasized the need for continued collaboration and transparency to strengthen defenses across the tech industry against sophisticated hacking campaigns.


Featured image: Koshiro K/Shutterstock

!function(f,b,e,v,n,t,s) {if(f.fbq)return;n=f.fbq=function(){n.callMethod? n.callMethod.apply(n,arguments):n.queue.push(arguments)}; if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0'; n.queue=[];t=b.createElement(e);t.async=!0; t.src=v;s=b.getElementsByTagName(e)[0]; s.parentNode.insertBefore(t,s)}(window, document,'script', 'https://connect.facebook.net/en_US/fbevents.js');

if( typeof window.sopp != "undefined" && window.sopp === 'yes' ){ fbq('dataProcessingOptions', ['LDU'], 1, 1000); } console.log('load_px'); fbq('init', '1321385257908563');

fbq('track', 'PageView');

fbq('trackSingle', '1321385257908563', 'ViewContent', { content_name: 'microsoft-blocked-hackers-government-agency-emails', content_category: 'news security' }); } });





Source link

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

We Know You Better!
Subscribe To Our Newsletter
Be the first to get latest updates and
exclusive content straight to your email inbox.
Yes, I want to receive updates
No Thanks!
close-link

Subscribe to our newsletter

Sign-up to get the latest marketing tips straight to your inbox.
SUBSCRIBE!
Give it a try, you can unsubscribe anytime.