Microsoft says Russian hackers breached its systems, accessed source code
bleepingcomputer.com
bleepingcomputer.com
Now: "This has included access to some of the company's source code repositories and internal systems. To date we have found no evidence that Microsoft-hosted customer-facing systems have been compromised.
It is apparent that Midnight Blizzard is attempting to use secrets of different types it has found. Some of these secrets were shared between customers and Microsoft in email, and as we discover them in our exfiltrated email, we have been and are reaching out to these customers to assist them in taking mitigating measures"
The constant downplaying at every stage puts a bad taste in the mouth. Three weeks from now we'll probably be talking about how "a small number of customer accounts have been compromised"
yborg said it right: https://news.ycombinator.com/item?id=39063441
When it comes to disclosing hacks, standard practice is to disclose a limited hack first, then when the hoopla dies down, disclose that the hack was "worse than previously thought".
[1] https://circles.page/5680a56b5c28af0998656e09/Hacks-worse-th...
Think how your customers would react if they were hacked and harmed. It is paramount that you err on the side of caution otherwise your bank account might be negatively impacted if your customers exercise due caution and react appropriately to the news.
Just remember the slogan: “My money is more important than your safety.”
Oscar Wilde, The Importance of Being Earnest