Microsoft actions following attack by nation state actor Midnight Blizzard
msrc.microsoft.com
msrc.microsoft.com
I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
1% of 238,000 employees is a "very small percentage" and still 2,380 employees. Insight into certain operational information and potentially undisclosed/unpatched zero days could be monumentally valuable to a nation state actor.
"We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes"
In other words: Microsoft will adopt their own security standards. Curious whether their SOC reports mention these are optional?
Microsoft is pretty learning resistant lately. Always prioritize the spamming customers, I guess?
Azure was owned pretty hard a while back, very little was ever heard of it again.
Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?
Users are more than just things you milk for cash, they're people that trusted you and your product.
GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy?
This is vice-signaling.
It says nothing about users being compromised.
This is why they won’t do anything about it though ? Do you understand how it works ?
They’re not going to do anything about the consequences for the users until it impacts their profits.
Name one person who is done with Microsoft after this?
Making my point. It doesn't mean users weren't compromised. And even if it did, that doesn't make it so for every security breach.
From what I recall, it was a Chinese APT (designated as Storm-0558, which I think means they could not reliably attribute it to any group: https://malpedia.caad.fkie.fraunhofer.de/actor/storm-0558), that was sitting on developers’ workstations long enough to get access to master signing key from a memory dump that ended up on one of the workstations. They then used it to access US government officials’ emails (Department of State if I recall correctly), which supposedly gave China a strategic advantage and a better understanding of inner workings of US foreign policy.
You will not see it in news that China got favourable terms in some negotiations with a country in Africa (are of Chinese interests) and US got least favourable terms than they could’ve gotten because the Chinese negotiators knew something.
... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
Yeah, at least they make a very small percentage of all Microsoft employees I guess"To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."
So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.
A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment.
From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
In the current context, this language is part of a pattern to carefully choose words in such a way as to downplay what has happened.
As I said, the work of the CEO, the cybersecurity team and the legal team is part of the overall production process at a software company.
But in general I would say routine janitorial maintenance issues don't have quite the same potential to affect production as Russian criminals reading the email of Microsoft's cybersecurity team.
Microsoft produces software and services. The communications of their CEO as well as their cybersecurity and legal teams is part of that overall production process.
It doesn’t matter to customers if Microsoft teams is down and we are talking to each other internally using iMessage and signal but anything that is in the data path is production.
In this instance, a system used by the cybersecurity team to do its actual job was breached - not some development or testing server.
We don't know what it was exactly that these attackers were looking for or what they found. But it is absolutely possible that the information they gained enables them to protect an ongoing or future attack against Microsoft's customers.
I’m going to take a wild guess here and say you don’t really run any kind of system. “Internal is not production” is the weirdest statement I have heard in a long time.
Of course these systems are production. Not only production, but _P1_ level production.
A system used by the cybersecurity team for its day to day work was breached by attackers constantly trying to break into customer systems.
[1] https://www.sec.gov/Archives/edgar/data/789019/0001193125240...
If folks are interested in this space, I just got the mailing list [2] running last night and you can see a list of all the current incidents on my Incident Tracker [3].
I have many more data points I plan on tracking as well as adding 10-K GRC items to the list (potentially helpful for CISOs, other risk managers and investors to eval a companies risk management maturity).
Welcome any feedback!
[1] https://www.board-cybersecurity.com/incidents/tracker/202401...
> The attack was not the result of a vulnerability in Microsoft products or services.
Hmm...
This is precisely the kind of 1990's level basic heuristic that this company cites as part of their Sentinel security system.
Trying to excuse a breach by 'the attacker tried a few passwords against lots of different accounts' is not compelling.
That's the most concerning fact that they just glossed over.
Non-production tenant PIVOT Satya’s email inbox. Like that.
2. Access non-prod environment
3. ???
4. "Look at me, look at me, I am the CEO now."
Seems like a big deal. Also, this may be why I've been getting massive amounts of "unusual account sign-in activity" emails for Microsoft about an old outlook account i no longer use...
Hopefully these state actors can get access to my vsts server i no longer can find and deploy an old app for me ;)
It's karma after years of my windows machine forcing a restart for a security update while I'm working on something in the middle of the day..
I also wonder if they had upgraded all of their Subscriptions to Defender for Cloud CSPM Tier 2 in order to use the premium Cloud Security Attack Graph explorer, and then enabled Workload protections, this tragedy could have been averted.
It’s going to take an army of motivated sales engineers to protect against these new cybernetic attacks by augmented warfighters.
If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.
(Which doesn't explain why it's on a Friday.)
there's thousands of ways to get exposure to MSFT one way or the other beyond the primary market
Why advantage parties that can process in less than 12 hours? Rushing analysis just makes it worse.
Ok, so far so good.
> including members of our senior leadership team
Ahhh, so maybe the attackers were after the senior leadership team and therefore stopped at the "very small percentage".
which is a very large number
> To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems.
senior executive's email accounts aren't production?
having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disaster that's just waiting to happen
I mean, given this was possible:
> used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts
pretty much anything is going to be better than letting Microsoft host your email/corporate data
With self-hosting you get to use thing now considered legacy (e.g., IMAP servers), but I definitely have seen them working for organisations with thousands of employees. You’ll need staff to support it, too, but at some scale it will none be more expensive than cloud services. Yet, you’ll have more control over it.
OTOH, some things will definitely be less feature-rich, for example, on-prem Sharepoint (not that I recommend using it) may not live up to the expectations of users familiar with the online version.
It's pretty embarrassing and not very reassuring that they themselves got owned, but they wanted to tell their customers that they didn't.
I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system internet facing? Why isn't MFA enforced?
https://learn.microsoft.com/en-us/sharepoint/delve-for-offic...
Microsoft365 is deprecating Delve in December 2024
A Nation-State is the idea of a homogenous nation governed by its own sovereign state—where each state contains one nation.
Does a non-production test account usually have permission to access email accounts of the senior leadership team? Is that a security best practice?
There are developers out there with excellent track records who have built bug-free solo projects which prove their excellence and yet can't find a job in this economy. Some of these developers have also proven themselves to work well in a team so there is no excuse to ignore them. They are excellent both as lone wolf and team player. Companies should desperately look for them and recruit them. Only such developers can save companies from technical decay.
How do they identify those groups?
Security people seems to be of the militaristic type ofent, so I guess they add a slive of war mongering to it to to play ball.
Iran, North Korea and what not. Very convenient since it is not falsifiable in practice.
"Modular implants with code reuse" - sounds like exploit kits you can buy on hacking forums.
This isn't a category argument, they're using a different one than what you can get on forums.
It’s ok to call them countries, hackers, and intrusions.
Microsoft got hacked by Russian government hackers.
I think it's possible that the truth is a little murky, and capturing that ambiguity is actually clearer than trying to wave it away
https://www.cisa.gov/topics/cyber-threats-and-advisories/adv...
So, they're "Russian Foreign Intelligence Service (SVR) cyber actors"
It's not if you want to do business in that country. Or if you annoy allies of that country (accusing certain countries might get senators breathing down your neck!). You are accusing a government of committing a crime, or at least a wildly unethical behavior. Those are huge charges. To your point, I wish they could be more direct, but...
> Microsoft got hacked by Russian government hackers.
It is not known whether this hacking group is private, government sponsored, or government run. They could be a private group that takes both private and government contracts.
If they were funded via government channels, who was it? A higher up person using their personal wealth? A specific agency? Multiple agencies?
The reason they are being so vague is because they don't know the answers, and it is very discrediting to throw around incorrect accusations.
Coming from Russia, that's a distinction without a difference.
Sure, private groups can 'freelance', but not without at least tacit permission from the FSB, GRU, and/or SVR (more accurately, cant freelance for long). Especially so for sch a high visibility target such as Microsoft.
And when the RU govt isdues a denial, it's confirmed.
But still no reason for MS to escalate the wording. They put enough in there that anyone with a clue knows it's serious.
Operating with tacit approval is not the same as being a government entity. Even you admit there is a small chance that this group is not tacitly approved ("for long"). I mean yeah, we all know the score, but a it's really bad idea to levy heavy charges without knowing the answer 100%.
This statement does pretty heavily implicate the Russian Govt though, yeah :)
>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.
“NOBELIUM is an advanced persistent threat group also known as APT29, which is publicly attributed to the Russian government and specifically to the Foreign Intelligence Service of the Russian Federation (SVR)”
https://blogs.blackberry.com/en/2023/03/nobelium-targets-eu-...
The only evidence I've seen before in cases like this one was that they found that the hacks happened during Russia's working hours (i.e. Moscow timezone), and that they found some word in Cyrillic in some of the shell scripts. Which is honestly not hard to pull off if you want to hide your true identity. Not saying Russia is not interested in those hacks, but a lot of far-reaching conclusions are often quickly made based on such weak assumptions.
Say some specific infrastructure is used to hack a law firm involved in prosecuting Russia for war crimes in Ukraine. Then that same infra is used to send disinfo targeting Ukrainian groups. Then the some distinct malware used in those attacks is also used to wipe machines in the Ukraine conflict. There are full time groups that track these indicators to tie one attack to another and distinguish groups. This group is likely the SVR.
[0] https://learn.microsoft.com/en-us/microsoft-365/security/int...
They all sound like bad translations to bargain-bin porno movies.
They even draw up supervillain graphics for them.
Why are we modelling threat actors/"adversaries" as a video game bestiary? Or meteorological phenomena in the case of MS?
Like, who is this made to appeal to? Is this meant to make corporate executive browsing for cybersecurity solutions feel like they're in a spy movie?
If so, hello Skynet.
Going back to my example with taxonomies: Yeah, you got bit by a spider, but exactly which kind of spider bit you? What do we know about those kinds of spiders, e.g. are they known for being venomous or not, does their bite have a well-known reaction in humans, etc.
https://www.theregister.com/2023/07/20/under_cisa_spressures...
Fine, I bet the password was Password123!, but then "they used account's permissions" to access various corporate emails. How is that even possible? What does it mean "they used the account's permissions"? Are you telling me there was no privilege separation between a tenant test environment and the internal domain? That the tenant system was not in its own isolated network? This is absolutely insane. Whenever I read stuff like that I wonder if some junior IT employee didn't just buy a new home for cash few months ago. I'm all for "don't look for malice where incompetence is a sufficient explanation", but that's just a little too much incompetence to be believable.
https://techcrunch.com/2024/01/19/hackers-breached-microsoft...
funny thing - if you have these things in default and someone deletes a user, you won't know who did such action after 30 days (meaning you not only can not recover the user, but also will not know who performed the action)
edit -as for the compliance, personally not aware of it, but you should be able to at least have a retention policy option for it and since most companies will just put it into a storage account or log analytics I don't think it's a matter of that
If people at Microsoft reuse passwords than what we can expect from casual PC users?!
Or intentionally obfuscated "we were hacked".
Why is this happening to English?
The other day, there was a story about an airplane window that got melt and many native speakers couldn't make sense of what the title of the story meant?
In that case too, as a non native speaker of English, I blamed myself first for not understanding the language well enough.
this presents no proof, but I’ve read lots of krebs security proof on other exploits and I think it is all very weak
nothing is stopping anybody here from putting breadcrumbs in a payload to point the finger at North Korea or a former Soviet state
This is kind of a silly standard that allows hackers to operate with impunity and companies to avoid accountability and the fbi from not bothering
I agree with you that seeing evidence would be nice, but I understand that there is the possibility that evidence supporting the claim exists and at the same time cannot be released to the public.
What other threat actor's internals (and I mean more then chat logs) have been made public?
I already conceded in my original response that if you hacked another group first, then yes, you can leave fake breadcrumbs.
And I'm also saying you don't necessarily need to hack another group to find their tools.