Award Banner
Award Banner

Microsoft uncovers new breach while investigating SolarWinds hackers

Microsoft uncovers new breach while investigating SolarWinds hackers
The headquarters of Microsoft France at Issy-les-Moulineaux, near Paris, on April 18, 2016.
PHOTO: Reuters

Microsoft said on Friday (June 25) an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.

The company said it had found the compromise during its response to hacks by a team it identifies as responsible for earlier major breaches at SolarWinds and Microsoft.

Microsoft said it had warned the affected customers. A copy of one warning seen by Reuters said the attacker belonged to the group Microsoft calls Nobelium and that it had access during the second half of May.

“A sophisticated Nation-State associated actor that Microsoft identifies as NOBELLIUM accessed Microsoft customer support tools to review information regarding your Microsoft Services subscriptions,” the warning reads in part. The US government has publicly attributed the earlier attacks to the Russian government, which denies involvement.

The SolarWinds headquarters in Austin, Texas, on December 18, 2020.
PHOTO: Reuters

When Reuters asked about that warning, Microsoft announced the breach publicly.

After commenting on a broader phishing campaign it said had compromised a small number of entities, Microsoft said it had also found the breach of its own agent, who it said had limited powers.

The agent could see billing contact information and what services the customers pay for, among other things.

“The actor used this information in some cases to launch highly-targeted attacks as part of their broader campaign,” Microsoft said.

Read Also
digicult
Ransom-seeking hackers are taking advantage of Microsoft flaw: Expert

Microsoft warned affected customers to be careful about communications to their billing contacts and consider changing those usernames and email addresses, as well as barring old usernames from logging in.

Microsoft said it was aware of three entities that had been compromised in the phishing campaign.

It did not immediately clarify whether any had been among those whose data was viewed through the support agent, or if the agent had been tricked by the broader campaign.

Microsoft did not say whether the agent was at a contractor or a direct employee.

A spokesman said the latest breach by the threat actor was not part of Nobelium’s previous successful attack on Microsoft, in which it obtained some source code.

In the SolarWinds attack, the group altered code at that company to access SolarWinds customers, including nine US federal agencies.

At the SolarWinds customers and others, the attackers also took advantage of weaknesses in the way Microsoft programs were configured, according to the Department of Homeland Security.

Microsoft later said the group had compromised its own employee accounts and taken software instructions governing how Microsoft verifies user identities.

A White House official said the latest intrusion and phishing campaign was far less serious than the SolarWinds fiasco.

“This appears to be largely unsuccessful, run-of-the-mill espionage,” the official said.

ALSO READ: Microsoft says Chinese hackers used flaws in its software to steal emails

Scott McConnell, a spokesman for Homeland Security’s Cyber security and Infrastructure Security Agency, said the defensive group “is working with Microsoft and our inter-agency partners to evaluate the impact. We stand ready to assist any affected entities.”

A SolarWinds spokesperson said, “The latest cyber attack reported by Microsoft does not involve our company or our customers in any way.”

homepage

trending

trending
    Taiwan's popular noodle chain Xiao Hun Mian opens first Singapore outlet at Raffles City
    Him Law explains the 'enjoyment' of playing villainous characters
    'I feel incredibly honoured': Drum major who dreamed of role as teen leads Singapore Police Force Band in centennial celebration
    Thai actor Nonkul loses mother to cancer shortly before birthday, cancels fanmeet
    East-West Line disruption: SMRT to be fined $3m for September 2024 incident
    Cool paint, clean power: These are the sustainable innovations that Temasek Foundation is backing for $2m
    New resort chalet run by co-living brand Coliwoo to open in Pasir Ris
    We asked frequent concertgoers what makes the ultimate concert experience – here's what they said
    Ayumi Hamasaki denies Elon Musk fathered her child
    Online claims about Covid-19 autopsy and vaccination laws are false: MOH
    ICA issues verbal advisory to sole voter in Tampines Changkat SMC polling district for failing to update address
    In-store navigation and personalised recommendations: FairPrice trials smart trolleys in pilot plan to integrate AI

Singapore

Singapore
    • PHV drivers rally to raise funds after Grab driver dies suddenly, leaving behind 2 children
    • Enforcement officer lays tape measure on road to assess illegal parking, impresses netizens
    • 14-year-old student, 5 foreigners among 139 arrested in $630k islandwide drug bust
    • 1.2 tonnes of illegally imported fresh and processed produce seized at Tuas Checkpoint
    • Beach Road slashing: Man gets 19 years' jail, caning for attempted murder of wife
    • Fallen tree, debris all over: 3 taken to hospital following Hougang road accident
    • $1,097 for 3 pieces: Woman calls cop over clothing bill at Far East Plaza shop
    • 12-year-old girl locks herself in room, police negotiators called in
    • Parts of Hougang hit by power outage; SP Group apologises
    • 'We didn't think twice': SBS Transit staff return bag containing $10k to passenger within an hour

Entertainment

Entertainment
    • Hong Kong celebrity couple Benjamin Yuen and Bowie Cheung expecting second baby
    • 'I made a fool of myself': Malaysian woman trying to buy G-Dragon concert tickets accidentally buys ones for Kenny G
    • Zhang Zhenhuan's daughter, 3, tries out acting, gets visit to Shanghai Disneyland as reward
    • 'We will sue him until he goes bankrupt': Victim's mother plans to sue ex-actor Ian Fang
    • Shirley Manson 'doesn't care' if she is cancelled
    • TXT pop-up store at Plaza Singapura opens in June
    • King of the Hill star Jonathan Joss, 59, dies in shooting
    • Rod Stewart cancels his Las Vegas concert 'due to illness'

Lifestyle

Lifestyle
    • Unable to bear children, she proposed annulment of marriage so he could start a family. He chose love
    • Miss World 2025 sees first winner from Thailand - meet the political science student who champions breast cancer awareness
    • Jurassic World, inflatable playgrounds and more: Family-friendly events and activities this June holiday
    • Porridge, pancakes and more: Popeyes enters Singapore's fast-food breakfast game
    • Kyoto's viral Kichi Kichi Omurice chef is coming to Singapore, here's how you can meet him
    • Is Phnom Penh Southeast Asia's most underrated capital? Here's why it is time to visit
    • Micromanaged, mothered and finally free – learning to love mum from afar
    • We tour freehold landed homes within 1km of Tao Nan & CHIJ Katong (from $3.88m in 2021)
    • Double trouble: Singapore's first tag-team twins make their pro wrestling debut
    • Uncovering the secrets behind Chagee’s best-selling jasmine green milk tea

Digicult

Digicult
    • Slim, sleek, but slightly too short-lived: Samsung Galaxy S25 Edge review
    • World's best Dota 2 teams to compete for $1m prize pool in Singapore in November
    • A $500 wake-up call: How the Samsung Galaxy Ring made me realise my stress
    • Monster Hunter Wilds producer explains how game has remained unique and fresh over 20 years
    • Initiative by IMDA, AI Verify Foundation tests AI accuracy, trustworthiness in real-world scenarios
    • Under siege? Helldivers 2's latest city to be invaded by aliens could be spoof of Singapore
    • Honor 400 Series launches in Singapore with first free in-device AI image-to-video tool
    • Home Team humanoid robots to be deployed by mid-2027, $100m to be invested: Josephine Teo
    • Ado concert review: Singer without a face ignites fans while in cage with only silhouette visible
    • EU and US authorities take down malware network

Money

Money
    • Wall Street equity indexes close higher after US-China tariff truce
    • Giant deal: Malaysian company to acquire Cold Storage and Giant supermarket chains in Singapore
    • 4-room HDBs without million-dollar sales - where to still find value today
    • $1.16m for a 4-room HDB flat in Clementi? Why this integrated development commands premium prices
    • Why these buyers chose older leasehold condos — and have no regrets
    • Can you still own multiple properties in Singapore? Here's what you need to know in 2025
    • Selling your home for the first time? Here's a step-by-step timeline to follow in Singapore
    • Why some central 2-bedroom homeowners in Singapore are stuck
    • How the interest rate cycle works - and what it means for your home loan
    • Tampines, Sengkang and more towns set new 2-room all-time-high records - is this part of a broader trend?

Latest

Latest
  • Daily roundup: FairPrice trials smart trolleys in pilot plan to integrate AI — and other top stories today
  • Dutch far-right leader Wilders quits coalition, toppling government
  • Australian woman accused of triple mushroom murders breaks down in court
  • At least 27 Palestinians killed near Gaza aid site, medics say
  • Medvedev says Russia seeks victory, not compromise, in talks with Ukraine
  • Over 200 prisoners break out of Pakistani jail after earthquake panic, says official
  • Myanmar junta extends temporary ceasefire to June 30
  • Rwanda-backed rebels in Congo executed civilians, Human Rights Watch says
  • Mongolian PM resigns after losing parliament backing, street protests

In Case You Missed It

In Case You Missed It
  • Over 170 travellers nabbed for evading GST, smuggling large sums of cash in island-wide operation
  • Woman crawls out of storm drain in shocking Manila street scene
  • DBS staff, police stop 2 victims from losing $820k to government official impersonation scams
  • 'Be humble in victory': PM Wong sends traditional 'Rules of Prudence' letter to PAP MPs after GE
  • Pedestrian, 84, dies in accident involving minibus in Choa Chu Kang
  • NDP 2025 marks SG60 with expanded celebrations from Padang to Marina Bay
  • Obesity rates are rising in Singapore, but is overeating the only cause?
  • Trump administration blocks Harvard from enrolling foreign students, threatens broader crackdown 
  • 'We apologise for the operational lapse': NUS responds to backlash over disposal of Yale-NUS books
This website is best viewed using the latest versions of web browsers.