hometechnology NewsHow Russian hackers broke into email accounts of some top Microsoft employees

How Russian hackers broke into email accounts of some top Microsoft employees

The hackers tried out a password on a bunch of accounts they had acquired. They repeated the process with new passwords until they breached some of the accounts, including those of senior leaders at Microsoft.

Profile image

By Sriram Iyer  Jan 20, 2024 7:45:05 AM IST (Updated)

Listen to the Article(6 Minutes)
2 Min Read
How Russian hackers broke into email accounts of some top Microsoft employees
In late November 2023, hackers backed by the Russian government used password spray attack to access emails of some Microsoft employees including some members of the senior leadership team, the world's largest software maker revealed.

'Spray attack' is the process in which the hackers tries out a password a bunch of usernames they have acquired. It repeats the process with new passwords until they breakthrough.
According to company led by Chairman Satya Nadella, the threat was detected on January 12. "We are in the process of notifying employees whose email was accessed," the company in a blog.
The company blog identified the hackers as Midnight Blizzard, also known as Nobelium, a Russian state-sponsored group.
Midnight Blizzard is reportedly the same group that managed to hack into a software created by Texas-based SolarWinds to spy on US government agencies and some top companies for nine months in 2020.
Microsoft warned users in August there were phishing attempts on the users of Microsoft Teams.
What is a phishing attack?
“The attack was not the result of a vulnerability in Microsoft products or services,” according to post. “To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems. We will notify customers if any action is required.”
Last month, a new rule set by the U.S. Securities and Exchange Commission came into effect. Listed companies have to disclose breaches that could negatively impact their business within four days unless they have a national-security waiver.

Most Read

Share Market Live

View All
Top GainersTop Losers
CurrencyCommodities
CurrencyPriceChange%Change