Security News > 2024 > January > What Microsoft's latest email breach says about this IT security heavyweight

Microsoft declined to answer The Register's questions about the digital heist, or its security in general.
This marks the second time since 2020 the same gang of Kremlin-backed cyber spies - whom Microsoft now calls Midnight Blizzard, used to track as Nobelium, and most call Cozy Bear - has invaded Microsoft.
Following the theft of the Microsoft security key that China used to break into US government email accounts in July - and at the urging of US Senator Ron Wyden - the US Cyber Safety Review Board launched an investigation into the Microsoft breach and the larger issues surrounding cloud security.
Presumably, the review board had begun its Microsoft analysis when Cozy Bear broke into corporate email accounts last year.
Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account's permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
"It is inexcusable that Microsoft still hasn't required multi-factor authentication, which is cybersecurity 101 and would have prevented this latest attack," Wyden told The Register.
News URL
https://go.theregister.com/feed/www.theregister.com/2024/01/24/microsoft_latest_breach_cozy_bear/
Related news
- Microsoft Warns of Tax-Themed Email Attacks Using PDFs and QR Codes to Deliver Malware (source)
- April 2025 Patch Tuesday forecast: More AI security introduced by Microsoft (source)
- Google's got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft's $20B+ security biz (source)
- Microsoft: Windows 'inetpub' folder created by security fix, don’t delete (source)
- Widespread Microsoft Entra lockouts tied to new security feature rollout (source)
- Microsoft Secures MSA Signing with Azure Confidential VMs Following Storm-0558 Breach (source)
- Microsoft fixes machine learning bug flagging Adobe emails as spam (source)
- Microsoft fixes Exchange Online bug flagging Gmail emails as spam (source)
- 3AM ransomware uses spoofed IT calls, email bombing to breach networks (source)