Russian Hacker Group Breaches Microsoft Email Accounts: CISA Issues Emergency Directive

Russian Hacker Group Breaches Microsoft Email Accounts: CISA Issues Emergency Directive

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an alarming directive regarding a Russian hacker group, Midnight Blizzard, which successfully breached a number of

Microsoft corporate email accounts. According to CISA, Midnight Blizzard exfiltrated email correspondence between Federal Civilian Executive Branch (FCEB) agencies and Microsoft, posing a significant risk to government agencies.

The breach involved the compromise of Microsoft corporate email accounts, allowing the threat actors to access authentication details shared between Microsoft customers and the company via email. This compromised information was then leveraged to gain further access to Microsoft customer systems, raising serious security concerns.

CISA's emergency directive, issued on April 11, underscores the gravity of the situation and mandates affected agencies to review and enhance their security measures. The directive requires agencies to analyze exfiltrated email content, reset compromised credentials, and bolster security for privileged Microsoft Azure accounts.

While the extent of the damage and the specific information accessed by Midnight Blizzard remains undisclosed, both CISA and Microsoft have notified affected agencies. Midnight Blizzard, also known as Nobelium and Cozy Bear, has been linked to Russia's Foreign Intelligence Service (SVR), according to Microsoft's cybersecurity report on Ukraine from June 2022.

This incident follows Microsoft's report in January, which revealed that Midnight Blizzard had exfiltrated emails, documents, and gained access to source code repositories and internal systems since November 2023. The group has been known to employ password-spraying attacks, targeting multiple accounts with commonly used passwords in brute-force attacks.

Midnight Blizzard gained infamy for its involvement in the 2020 SolarWinds hack, which compromised several US federal agencies. The ongoing threat posed by such state-sponsored hacker groups underscores the importance of robust cybersecurity measures to safeguard sensitive information and critical infrastructure.

Hanzala Sardar

Hello, NewsPro readers! I'm Hanzala Sardar, a passionate writer dedicated to bringing you the latest and most compelling news stories. With a keen eye for detail and a commitment to delivering accurate and insightful content, I strive to keep you informed and engaged.

Post a Comment

Please Select Embedded Mode To Show The Comment System.*

Previous Post Next Post

Contact Form