HomeSecurityMicrosoft: Russian hackers Nobelium breached its emails

Microsoft: Russian hackers Nobelium breached its emails

Microsoft says Russian hackers, known as Midnight Blizzard (Nobelium or APT29), compromised some corporate email accounts and stole data . The company detected the attack on January 12.

Microsoft email hacked

Microsoft says that attackers breached its systems in November 2023, as part of a password spray attack (a type of brute force), to access an old non-production test tenant account.

The fact that hackers were able to gain access to the account using a brute force attack indicates that there was no protection with two-factor authentication (2FA) or multi-factor authentication (MFA).

According to the company, after accessing the “test” account, Russian hackers Nobelium used it to gain access to a “small percentage” of Microsoft corporate email accounts for more than a month.

See also: VF Corporation: Ransomware attack led to data breach of 35 million people

Microsoft says the compromised email accounts included members of Microsoft's leadership team and employees in its cybersecurity and legal departments. Through their access, the hackers were able to steal emails and attachments.

“ Investigation indicates that they initially targeted email accounts for information related to Midnight Blizzard itself ,” the company says

Microsoft also stated that it is in the process of notifying employees whose email was affected.

The company emphasized that the breach of emails occurred through a brute force attack and not due to any vulnerability in its products and services.

However, based on the limited information disclosed by Microsoft, it appears that a large part of the breach was caused by the improper protection of the test account.

Russian hackers Nobelium

The Nobelium group (also known as Midnight Blizzard, APT29, and Cozy Bear) is a Russian state-sponsored hacking group believed to be part of Russia's Foreign Intelligence Service (SVR).

The hackers became more well-known when they were linked to the SolarWinds in 2020, which had, at the time, affected Microsoft. Microsoft later confirmed that the SolarWinds attack allowed hackers to steal source code for a limited number of Azure, Intune, and Exchange components.

See also: Framework Computer: Suffered a data breach

Russian hackers Nobelium

In June 2021, the hacking group breached a Microsoft corporate account once again.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

These Russian hackers are primarily engaged in cyberespionage and data theft, but they are also known for developing custom malware for their attacks.

How can a company protect itself from similar attacks?

To protect a company from such attacks, it must first be constantly updated on the latest techniques and methods used by Russian hackers. This can be done through specialized training programs and continuous updates.

It is also important to have a strong security systemin place. This includes using advanced security software, implementing security , and protecting networks and systems from attacks.

See also: Fidelity National Financial: Data breach affects 1.3 million people

Staff training is also crucial. Employees need to be aware of the risks and techniques hackers use, such as phishing , and how to deal with them.

Perhaps the most important protection measure that could have prevented the Microsoft account breach is two-factor authentication , which the company recommends to all its customers.

Finally, implementing the principle of least privilege (PoLP) can help protect sensitive information. This means that users only have the permissions they need to perform their tasks, thereby limiting access to data.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS