U.S. Federal Agencies Ordered to Hunt for Signs of Microsoft Breach and Mitigate Risks

Share:

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday issued an emergency directive (ED 24-02) urging federal agencies to hunt for signs of compromise and enact preventive measures following the recent compromise of Microsoft’s systems that led to the theft of email correspondence with the company.

The attack, which came to light earlier this year, has been attributed to a Russian nation-state group tracked as Midnight Blizzard (aka APT29 or Cozy Bear). Last month, Microsoft revealed that the adversary managed to access some of its source code repositories but noted that there is no evidence of a breach of customer-facing systems.

The emergency directive, which was originally issued privately to federal agencies on April 2, was first reported on by CyberScoop two days later.

“The threat actor is using information initially exfiltrated from the corporate email systems, including authentication details shared between Microsoft customers and Microsoft by email, to gain, or attempt to gain, additional access to Microsoft customer systems,” CISA said.

The agency said the theft of email correspondence between government entities and Microsoft poses severe risks, urging concerned parties to analyze the content of exfiltrated emails, reset compromised credentials, and take additional steps to ensure authentication tools for privileged Microsoft Azure accounts are secure.

It’s currently not clear how many federal agencies have had their email exchanges exfiltrated in the wake of the incident, although CISA said all of them have been notified.

The agency is also urging affected entities to perform a cybersecurity impact analysis by April 30, 2024, and provide a status update by May 1, 2024, 11:59 p.m. Other organizations that are impacted by the breach are advised to contact their respective Microsoft account team for any additional questions or follow up.

“Regardless of direct impact, all organizations are strongly encouraged to apply stringent security measures, including strong passwords, multi-factor authentication (MFA) and prohibited sharing of unprotected sensitive information via unsecure channels,” CISA said.

The development comes as CISA released a new version of its malware analysis system, called Malware Next-Gen, that allows organizations to submit malware samples (anonymously or otherwise) and other suspicious artifacts for analysis.

Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:55 am, Jan 29, 2025
weather icon 6°C
L: 5° | H: 7°
few clouds
Humidity: 88 %
Pressure: 1000 mb
Wind: 12 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:43 am
Sunset: 4:43 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
5° | 7°°C 0.32 mm 32% 7 mph 85 % 1007 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 7°°C 0 mm 0% 9 mph 84 % 1026 mb 0 mm/h
Fri Jan 31 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 4 mph 79 % 1036 mb 0 mm/h
Sat Feb 01 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 6 mph 86 % 1037 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 4 mph 76 % 1029 mb 0 mm/h
Today 6:00 am
weather icon
6° | 7°°C 0 mm 0% 7 mph 85 % 1000 mb 0 mm/h
Today 9:00 am
weather icon
6° | 6°°C 0 mm 0% 7 mph 81 % 1002 mb 0 mm/h
Today 12:00 pm
weather icon
8° | 8°°C 0 mm 0% 3 mph 69 % 1003 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 3 mph 72 % 1003 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 7°°C 0.32 mm 32% 4 mph 84 % 1005 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 5 mph 84 % 1007 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 84 % 1010 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 9 mph 84 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,831.36
-0.77%
Ethereum(ETH)
€2,993.58
-2.89%
XRP(XRP)
€2.95
-0.25%
Tether(USDT)
€0.96
-0.02%
Solana(SOL)
€221.96
-2.60%
USDC(USDC)
€0.96
-0.01%
Dogecoin(DOGE)
€0.314723
-2.37%
Shiba Inu(SHIB)
€0.000017
-4.52%
Pepe(PEPE)
€0.000012
-7.77%
Scroll to Top