Microsoft uncovers new breach while investigating SolarWinds hackers

Microsoft uncovers new breach while investigating SolarWinds hackers
The headquarters of Microsoft France at Issy-les-Moulineaux, near Paris, on April 18, 2016.
PHOTO: Reuters

Microsoft said on Friday (June 25) an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.

The company said it had found the compromise during its response to hacks by a team it identifies as responsible for earlier major breaches at SolarWinds and Microsoft.

Microsoft said it had warned the affected customers. A copy of one warning seen by Reuters said the attacker belonged to the group Microsoft calls Nobelium and that it had access during the second half of May.

“A sophisticated Nation-State associated actor that Microsoft identifies as NOBELLIUM accessed Microsoft customer support tools to review information regarding your Microsoft Services subscriptions,” the warning reads in part. The US government has publicly attributed the earlier attacks to the Russian government, which denies involvement.

The SolarWinds headquarters in Austin, Texas, on December 18, 2020.
PHOTO: Reuters

When Reuters asked about that warning, Microsoft announced the breach publicly.

After commenting on a broader phishing campaign it said had compromised a small number of entities, Microsoft said it had also found the breach of its own agent, who it said had limited powers.

The agent could see billing contact information and what services the customers pay for, among other things.

“The actor used this information in some cases to launch highly-targeted attacks as part of their broader campaign,” Microsoft said.

Read Also
digicult
Ransom-seeking hackers are taking advantage of Microsoft flaw: Expert

Microsoft warned affected customers to be careful about communications to their billing contacts and consider changing those usernames and email addresses, as well as barring old usernames from logging in.

Microsoft said it was aware of three entities that had been compromised in the phishing campaign.

It did not immediately clarify whether any had been among those whose data was viewed through the support agent, or if the agent had been tricked by the broader campaign.

Microsoft did not say whether the agent was at a contractor or a direct employee.

A spokesman said the latest breach by the threat actor was not part of Nobelium’s previous successful attack on Microsoft, in which it obtained some source code.

In the SolarWinds attack, the group altered code at that company to access SolarWinds customers, including nine US federal agencies.

At the SolarWinds customers and others, the attackers also took advantage of weaknesses in the way Microsoft programs were configured, according to the Department of Homeland Security.

Microsoft later said the group had compromised its own employee accounts and taken software instructions governing how Microsoft verifies user identities.

A White House official said the latest intrusion and phishing campaign was far less serious than the SolarWinds fiasco.

“This appears to be largely unsuccessful, run-of-the-mill espionage,” the official said.

ALSO READ: Microsoft says Chinese hackers used flaws in its software to steal emails

Scott McConnell, a spokesman for Homeland Security’s Cyber security and Infrastructure Security Agency, said the defensive group “is working with Microsoft and our inter-agency partners to evaluate the impact. We stand ready to assist any affected entities.”

A SolarWinds spokesperson said, “The latest cyber attack reported by Microsoft does not involve our company or our customers in any way.”

homepage

trending

trending
    'Our role is to make ourselves obsolete': First-time WP candidates reflect on GE2025 and whether they'll run again
    E-Junkies: Members of new K-pop girl group Kiiras put teen life on hold for idol career
    Senior Malaysian army officers who allegedly masterminded smuggling syndicate busted
    Mariah Carey, Treasure, Eric Moo: Singapore concert calendar for 2025
    Scoot launching new flights to Japan, including Okinawa, and Thailand from December; tickets from $128
    Jimmy Kimmel has obtained Italian citizenship
    Shoelace to tie umbilical cord: Woman in Malaysia goes into labour by roadside, passing motorists help deliver baby
    Jail for woman who forged medical documents in bid to quickly withdraw her CPF funds
    New Hawkers' Street outlet at Tangs Plaza features 6 Michelin-recognised brands, opens on Aug 18
    Jacelyn Tay gifts her Star Awards trophies to long-time fan
    Malaysia's top court dismisses appeal against jailed ex-PM Najib's house arrest bid
    'I would be crying every day during lunch': Rebecca Lim recalls feeling inadequate in 1st acting role after childbirth

Singapore

Singapore
    • Singapore upgrades 2025 growth forecast but warns that outlook remains 'clouded by uncertainty'
    • 2 Singapore drivers allegedly detained in Legoland for offering illegal ride-hailing services; cars seized
    • Singapore delivers ninth tranche of humanitarian aid to Gaza
    • 'Proof of love between 2 nations': Malaysian man creates SG60 shirt to thank Singaporeans who helped him through hard times
    • Off-duty SCDF officer killed in Punggol crash; 15-year-old taken to hospital
    • 'We have to be ready anywhere, anytime': Off-duty healthcare professionals from Singapore revive elderly man in JB
    • Johor govt seeking stricter laws against foreign drivers misusing subsidised fuel
    • Service on North East Line resumes
    • Singaporean woman deported from Malaysia
    • PM Wong to deliver National Day Rally speech on Aug 17

Entertainment

Entertainment
    • Huang Zitao and Xu Yiyang to hold wedding in October with 100 fans in attendance
    • Zheng Geping awarded Public Service Medal for contributions to Woodlands CCC
    • Blackpink's Jisoo releases Your Love special video filmed at Rainforest Wild Asia in Mandai
    • 'My sweat seeped through the seams': Zhang Zetong on 'suffering' and working with new virtual technology for drama Perfectly Imperfect
    • Taylor Swift announces new album called The Life of a Showgirl
    • Noah Centineo to star in Rambo origins movie
    • Maluma stops concert to reprimand fan who brought along a baby
    • 'I felt I would die if I closed my eyes': Ada Choi's husband Max Zhang recalls suffering heart attack in April
    • Tom Holland admits putting on his Spider-Man suit 'feels different this time'
    • Jet Li's eldest daughter getting married

Lifestyle

Lifestyle
    • Ong Ye Kung rebuts KF Seetoh's claims regarding treatment of stallholders at Bukit Canberra Hawker Centre
    • Popular Japanese restaurant Shaburi & Kintan Buffet to shutter after 9 years
    • Singapore ranks top in Asia for work-life balance and 25th in the world, according to Remote study
    • Embracing Singlish as part of our identity: Paiseh for what?
    • BYD Atto 2 electric compact SUV launched in Singapore
    • I've lived in Twin Vew for 4 years: What's it like living without an MRT station nearby
    • Even cheaper than Bali: 5 hidden Asian islands you (and your wallet) will love
    • 4 condo layouts and features buyers are moving away from in 2025
    • How to get your driving licence in Singapore - fast
    • 'Last' meals: How durian, chilli crab, and KFC bring comfort to the dying in Singapore

Digicult

Digicult
    • Slim, sleek, but slightly too short-lived: Samsung Galaxy S25 Edge review
    • World's best Dota 2 teams to compete for $1m prize pool in Singapore in November
    • Apple Maps brings 3D landmarks and road-level realism to Singapore
    • The best AI tutor for O-level subjects: ChatGPT, Gemini or The Wise Otter?
    • Vivo X Fold5: A foldable contender with a few class-leading surprises
    • Here's everything in GPT-5 that's new and different than OpenAI's previous AI models
    • Australia regulator says YouTube, others 'turning a blind eye' to child abuse material
    • ZipZap car subscription service launches in Singapore
    • Sony RX1R III brings back the compact full-frame but not the Sony playbook
    • China's Premier Li proposes global AI co-operation organisation

Money

Money
    • Up 4.3%: Singapore's economy grew in Q2 despite US tariff fears
    • Goh Cheng Liang, Nippon Paint billionaire and richest Singaporean, dies aged 98
    • StarHub buys rest of MyRepublic's broadband business in $105m deal; comes after Simba buys M1
    • Keppel to sell M1 unit's telco business to Simba for $1.43b
    • Singapore can deliver and thrive in a fragmented global economy: Morgan Stanley analysts
    • Over 70% of Ang Mo Kio's 4-room million-dollar resales in the past 3 years came from this project
    • DBS beats expectations with $2.82b net profit for second quarter, maintains 2025 outlook
    • Carro targets US IPO with over $3.8b valuation, sources say
    • US companies spending record amounts to protect executives as threats rise
    • Electric car-sharing firm BlueSG to wind down current operations on Aug 8

Latest

Latest
  • Daily roundup: Ex-NMP Calvin Cheng resolves differences with ex-SDP chairman over Gaza comments — and other top stories today
  • Russia has won war in Ukraine, Hungary's Orban says
  • South Korean President Lee to visit Japan for summit with PM Ishiba, Seoul says
  • Thai student, 17, kicks, rains blows on female teacher for not giving him full marks in exam
  • China's military says it 'drove away' US destroyer near Scarborough Shoal
  • New Zealand PM Luxon says Israel's Netanyahu has 'lost the plot'
  • Zelenskiy, European leaders to speak to Trump ahead of Putin summit
  • 'Cooked alive': Europe's wildfires hit tourism spots and forests
  • Mothers of Gaza hostages fear Israeli offensive will endanger their sons

In Case You Missed It

In Case You Missed It
  • Young Malaysian couple's first trip ends in tragedy after motorbike crashes on bend in Cameron Highlands
  • Man remanded after wielding knife, trying to snatch baby in Penang supermarket
  • Malaysia's border control agency gives ICA cake to mark SG60
  • Tourist in Hong Kong killed after cabby, 80, crashes into pillar outside hotel
  • 2 Malaysian men nabbed at Woodlands Checkpoint for allegedly smuggling drugs worth over $150k into Singapore
  • Parents reject $30k settlement from kindergarten in JB after son suffocates to death in school van
  • Pritam gets candid with kids’ questions on his worst subjects and favourite song in radio interview
  • Bro-code before go-mode: Meet the duo leading NDP 2025
  • LTA, Singapore bus operators reviewing Malaysia’s request to start services from JB at 4am
This website is best viewed using the latest versions of web browsers.