Security News > 2024 > January > What Microsoft's latest email breach says about this IT security heavyweight
Microsoft declined to answer The Register's questions about the digital heist, or its security in general.
This marks the second time since 2020 the same gang of Kremlin-backed cyber spies - whom Microsoft now calls Midnight Blizzard, used to track as Nobelium, and most call Cozy Bear - has invaded Microsoft.
Following the theft of the Microsoft security key that China used to break into US government email accounts in July - and at the urging of US Senator Ron Wyden - the US Cyber Safety Review Board launched an investigation into the Microsoft breach and the larger issues surrounding cloud security.
Presumably, the review board had begun its Microsoft analysis when Cozy Bear broke into corporate email accounts last year.
Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account's permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
"It is inexcusable that Microsoft still hasn't required multi-factor authentication, which is cybersecurity 101 and would have prevented this latest attack," Wyden told The Register.
News URL
https://go.theregister.com/feed/www.theregister.com/2024/01/24/microsoft_latest_breach_cozy_bear/
Related news
- Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks (source)
- Phishers send corrupted documents to bypass email security (source)
- Microsoft dangles $10K for hackers to hijack LLM email service (source)
- New fake Ledger data breach emails try to steal crypto wallets (source)
- Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API (source)
- UN aviation agency investigating 'potential' security breach (source)
- Washington state sues T-Mobile over 2021 data breach security failures (source)
- UN aviation agency confirms recruitment database security breach (source)
- 3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security Update (source)
- Microsoft shares temp fix for Outlook crashing when writing emails (source)