Hackers stole emails from several US federal agencies in an attack on Microsoft earlier this year, the country’s cybersecurity agency confirmed yesterday.
Microsoft revealed the attack in January, which was said to have been carried out by a Russian state-backed hacking group through corporate email accounts.
Known as Midnight Blizzard of ATP29, the group’s stack shocked intelligence agencies and led to the issue of a new directive this month warning of the threat of Russia-backed attacks while ordering companies to strengthen email protection.
“Midnight Blizzard’s successful compromise of Microsoft corporate email accounts and the exfiltration of correspondence between agencies and Microsoft presents a grave and unacceptable risk to agencies,” said the Cybersecurity and Infrastructure Security Agency (CISA).
The US government uses Microsoft extensively for its emails.
Microsoft is under pressure to demonstrate it has repelled the attack which it said in March was “ongoing” after a series of security lapses recently.
Last month, the US Cyber Safety Review Board (CSRB), an independent body from the government, slammed the software group for a “cascade of security failures” that allowed China-backed hackers to steal an email key that permitted broad access to both consumer and government emails.
In February, the US Department of Defense warned 20,000 people that information had been compromised after a Microsoft-hosted cloud email server was left unprotected for several weeks in 2023.