Shockwaves from the Russian government's hack of Microsoft's corporate infrastructure continue to spread with news that the software giant is notifying surprised customers that their emails were also stolen by the Midnight Blizzard hackers.
The mega-breach, which led to a US government investigation and a massive overhaul of Microsoft's security practices, was previously known to expose Microsoft source code and corporate emails but it appears that a larger base of the company's customers were among the victims.
According to published reports, Redmond's incident response team is providing a secure portal for customers to view specifics of emails stolen by the Midnight Blizzard threat actor.
While the full scope of the incident remains in flux, surprised customers posted screenshots of the latest Microsoft notifications on social media, confirming the hack had a broader impact on the company's customer base.
Midnight Blizzard/Nobelium is the same group that was attributed to hacking IT management solutions provider SolarWinds in a massive supply chain attack in 2020.
This Cyber News was published on www.securityweek.com. Publication date: Fri, 28 Jun 2024 18:13:05 +0000