Advertisement
Australia markets open in 8 minutes
  • ALL ORDS

    7,849.40
    +17.50 (+0.22%)
     
  • AUD/USD

    0.6572
    +0.0001 (+0.02%)
     
  • ASX 200

    7,587.00
    +17.10 (+0.23%)
     
  • OIL

    79.20
    +0.25 (+0.32%)
     
  • GOLD

    2,312.10
    +2.50 (+0.11%)
     
  • Bitcoin AUD

    90,020.34
    +1,150.65 (+1.29%)
     
  • CMC Crypto 200

    1,275.01
    +4.26 (+0.34%)
     

US Warns Agencies of Possible Breach Via Microsoft Hack

(Bloomberg) -- US federal agencies were ordered to analyze emails, reset compromised credentials and work to secure Microsoft Corp. cloud accounts amid concerns that a Russian nation-state hacking group may have accessed some correspondence.

Most Read from Bloomberg

The directive from the US Cybersecurity and Infrastructure Security Agency, known as CISA, came in response to breach of Microsoft that the tech giant disclosed in January. A Russian state-sponsored group called Midnight Blizzard was accused of exfiltrating data from Microsoft and using it to try compromise some of the company’s customers, according to the CISA alert. That includes correspondence between federal agencies and Microsoft, according to CISA.

ADVERTISEMENT

The emergency directive was initially issued on April 2 and made public Thursday.

Microsoft and CISA have notified all federal agencies whose emails may have been compromised by the hacking group, according to the government directive. It didn’t disclose the names or number of agencies.

The incident represents a “grave and unacceptable risk” to agencies, according to the directive.

A spokesperson for the Russian Embassy in Washington didn’t immediately respond to a request for comment.

Asked if the hacking campaign had been stopped, Eric Goldstein, executive assistant director at CISA, said the group poses a “persistent threat to organizations public and private.”

Federal agencies have until April 30 to reset credentials for related applications, and are also required to identify affected email correspondence by that deadline as well.

In January, Microsoft said it had been warning organizations that they were targets of the same Russian-sponsored group that hacked into sensitive corporate email accounts last year. The hackers — also known as Cozy Bear — have been identified by Microsoft’s threat intelligence team as the same cyber-espionage group that “has been targeting other organizations,” according to the January blog post.

Hewlett Packard Enterprise Co. also reported in January that it suffered a breach of its cloud-based email system that it said was likely caused by Midnight Blizzard.

The new US directive was previously reported by security news site CyberScoop.

--With assistance from Katrina Manson.

Most Read from Bloomberg Businessweek

©2024 Bloomberg L.P.