More companies expected to disclose email hacks by Russian intelligence

microsoft, more companies expected to disclose email hacks by russian intelligence

More companies expected to disclose email hacks by Russian intelligence

Security experts expect many more companies to disclose that they’ve been hacked by Russian intelligence agents who stole emails from executives following disclosures by Microsoft and Hewlett-Packard Enterprise in the past week.

Microsoft said late Thursday that it had found more victims and was in the process of notifying them. A spokesperson declined to say how many. But three experts in and out of government said that the attack was deeper and broader than the disclosures to date reveal.

Two said that more than 10 companies, and perhaps far more, are expected to come forward. The experts asked not to be named so as to maintain relations with the victims.

Changed Securities and Exchange Commission rules are driving the disclosures because the SEC now requires companies to notify their stockholders of computer breaches that could have a material impact on company results.

Microsoft, HPE and the experts said that Russia’s SVR foreign intelligence service have been inside the targeted companies for months. It was not clear whether the Russians had used the same technique repeatedly to gain access to the companies’ systems.

The SVR team, which Microsoft calls Midnight Blizzard, is regarded as one of the most proficient hacking forces in the world. Microsoft said the Russian agency had gotten a foothold inside its network by trying the same password on test accounts over and over until it found a match.

While that is a rudimentary attack, the company said it was made harder to spot because the login attempts came from a number of different places. Once inside, the hackers created new accounts and new apps with more internal powers.

Also known as Cozy Bear, the group last made international news for getting inside the software provider SolarWinds. It altered that company’s code, giving itself an entryway when federal agencies that were SolarWinds customers installed it.

“What sets this group apart is its remarkable combination of discretion, patience, and unwavering persistence, distinguishing them from other cyberthreat actors also funded and acting on behalf of nation-states,” said Aric Ward, a former threat analyst at the White House. “Their low profile is indicative of a stealthy and adept approach, making it clear that their actions persist even if they remain elusive from public scrutiny.”

The Microsoft and HPE breaches are especially concerning because so many other companies and agencies rely on them for cloud services, including email. It is not yet known whether the hackers were able to use their access to Microsoft’s systems to conduct attacks on other companies.

Alex Stamos, a security executive at competitor SentinelOne, said Microsoft’s most recent blog post indicated the company had used a detection technique that only works on Microsoft-hosted cloud services. Stamos wrote on LinkedIn that this suggested that multiple targets had been hit with an attack method that works against Microsoft’s system for authorizing access, now called Entra and formerly known as Azure Active Directory.

Microsoft said that the SVR searched through the email of its cybersecurity experts to find out what they knew about the Russian organization, which may reflect the company’s effectiveness in helping Ukraine deter cyberattacks since the invasion two years ago.

“It’s their goal to penetrate systems of interest to them, but given Microsoft’s role in the world and how helpful they have been to Ukraine, they’re going to be a target,” said George Barnes, who recently retired as the deputy director of the National Security Agency.

The Microsoft executives’ emails are also likely to contain conversations with government officials that would be useful for foreign intelligence agencies.

The Cybersecurity and Infrastructure Security Agency, the Homeland Security unit that tracks computer intrusions, did not respond to a request for comment.

News Related

OTHER NEWS

Lawsuit seeks $16 million against Maryland county over death of pet dog shot by police

A department investigator accused two of the officers of “conduct unbecoming an officer” for entering the apartment without a warrant, but the third officer was cleared of wrongdoing, the suit says. Read more »

Heidi Klum shares rare photo of all 4 of her and Seal's kids

Heidi Klum posted a rare picture with husband Tom Kaulitz and her four kids: Leni, 19, Henry, 18, Johan, 17, and Lou, 14, having some quality family time. Read more »

European stocks head for flat open as markets struggle to find momentum

This is CNBC’s live blog covering European markets. European markets are heading for a flat open Tuesday, continuing lackluster sentiment seen at the start of the week in the region ... Read more »

Linda C. Black Horoscopes: November 28

Nancy Black Today’s Birthday (11/28/23). This year energizes your work and health. Faithful domestic routines provide central support. Shift directions to balance your work and health, before adapting around team ... Read more »

Michigan Democrats poised to test ambitious environmental goals in the industrial Midwest

FILE – One of more than 4,000 solar panels constructed by DTE Energy lines a 9.37-acre swath of land in Ann Arbor Township, Mich., Sept. 15, 2015. Michigan will join ... Read more »

Gaza Is Falling Into ‘Absolute Chaos,’ Aid Groups Say

A shaky cease-fire between Israel and Hamas has allowed a surge of aid to reach Palestinians in Gaza, but humanitarian groups and civilians in the enclave say the convoys aren’t ... Read more »

Bereaved Israeli and Palestinian families to march together in anti-hate vigil

Demonstrators march against the rise of antisemitism in the UK on Sunday – SUSANNAH IRELAND/REUTERS Bereaved Israeli and Palestinian families will march together as part of an anti-hate vigil on ... Read more »
Top List in the World