A few days ago, Microsoft said that a group of hackers, supported by the Iranian government, attempted to compromise the email of former and current US government officials, mainly targeting members of a 2020 election campaign.
Microsoft Vice President Tom Burt said the attacks took place between August and September and lasted a full month.
According to Microsoft, the attacks are linked to a group the company calls Phosphorous. The group is also known as APT35, Charming Kitten, and Ajax Security Team. The hackers have previously been linked to the Iranian government.
Burt said the attacks were multi-stage. Initially, the hackers conducted more than 2,700 scans to identify email accounts belonging to specific Microsoft customers.
After obtaining a list of desired targets, they attempted to hack into 241 accounts, which were linked to a US and belonged to former and current government officials, as well as journalists covering political issues and prominent Iranians living outside Iran.
The hackers eventually managed to compromise four accounts, which were not related to the US presidential election or government officials.

The company made sure to inform all users about the breaches and helped victims protect their accounts.
According to the company, the hackers gained access to the accounts through the victims' secondary inbox. The victims also used a second email for their Microsoft account, which the hackers gained access to
The hackers then reset the password and used the reset link, received in the secondary inbox, to gain access to the primary Microsoft account.
Microsoft recommends that users involved in political campaigns, think tanks, or NGOs sign up for Microsoft AccountGuard, a special service from the company that is part of the Defending Democracy program.
Accounts that belong to AccountGuard have access to some features security, while also receiving notifications about potential threats. Already over 26,000 accounts from 26 countries have registered with AccountGuard.
“To date, we have sent more than 800 notifications of attempted government hacking attacks to AccountGuard customers,” said Burt.
This is not the first time the Phosphorus group has engaged Microsoft. In March, the company took control of 99 web domains that the group was using for spear-phishing campaigns.
