HomeSecurityMicrosoft Office 365 is becoming a more common target for hackers

Microsoft Office 365 is becoming a more common target for hackers

The use of Microsoft Office 365 is constantly increasing and the huge amount of data stored in the cloud is becoming a particularly tempting target for hackers according to FireEye Mandiant.

Office 365

As Doug Bienstock , principal security consultant at Mandiant, said , “the volume of data in Office 365 is simply enormous, and attackers are obviously interested in the data . But they can also now access that data from almost anywhere in the world.”

“Office 365 is also a gateway for organizations to access other applications as a single sign-on platform,” explained Bienstock.

Hackers usually have no trouble gaining access to systems . They can find lists of email addresses of a company's employees and try to carry out brute-force attacks to crack any common or weak passwords.

"The attacker will obtain these valid credentials, connect to the VPN , and infiltrate the network with the intent of escalating their privileges to a global administrator account for Office 365," said Josh Madeley, principal security consultant at Mandiant.

It is believed that a significant majority of state-backed APT groups are interested in developing this type of attack. However, one that is definitely interested is APT35, a hacking from Iran that is “notorious” for exploiting cloud services to gain access to sensitive information.

Hackers aren't trying to exploit a weakness in Office 365. But the way companies and users secure Office 365 could be improved to protect against such attacks. The first step organizations can take to prevent attacks is to ensure they don't use common or easily guessed passwords.

Organizations should also ensure that multi-factor authentication is implemented on as many employee accounts as possible, so in the event of a password theft or breach, there is an extra layer of defense to stop attacks. It is also recommended that organizations take the time to understand the activity on their networks, so it is possible to detect and stop suspicious activity before it causes significant damage.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS