Microsoft, endless problems with Russian cybercriminals

Microsoft, endless problems with Russian cybercriminals


Still problems between Microsoft and a Russian-backed cybercriminal group Midnight Blizzard who last November entered the email accounts of the company’s top executives, and was able to get his hands on a series of sensitive and confidential data. Last Friday, in fact, Microsoft said publicly that cybercriminals managed to steal some “secret” shared in email communications between the company and unspecified customers – such as passwords, certificates and authentication keys -, saying it has already contacted victims of the breach “help them take mitigation measures“.

A sustained Midnight Blizzard attack is characterized by a sustained and significant commitment to the threat actor’s resources, coordination, and focus. – writes Microsoft in update on the situation posted on his official blog – It can use the information obtained to gather a picture of attack sites and improve its ability to do so“. Therefore, the situation seems to be tense. Especially given that there are many institutional and corporate realities that they rely directly on Microsoft’s cloud network. “This has major implications for national security – commented Tom Kellermann of the cybersecurity company Contrast Security -. The Russians may now increase supply chain attacks against Microsoft customers.

The real problem, it seems, also lies in mismanagement of the situation on the part of the company, which in the past has not been very clear about the attacks suffered – and above all about the risks represented by the breach. Last November, for example, Microsoft said only that cybercriminals had accessed its corporate email system, without mentioning how many accounts were actually compromised. In subsequent communications, he admitted that he had been able to stop its activities only in January, when the criminals had managed to get all the data they needed. In short, the company does not seem to have been able to cope with the situation as well as it could have.