Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing." In an updated US SEC filing and companion security post, Microsoft provided more details about the security breach, which it first disclosed in January. At that time, Microsoft said Midnight Blizzard — the Kremlin-backed crew also known as Cozy Bear and APT29 that was behind the SolarWinds supply chain attack — snooped around in "a very small percentage of Microsoft corporate email accounts" and stole internal messages and files belonging to the leadership team, and cybersecurity and legal employees. "There is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems," Redmond said in January. That has since changed. "In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our corporate email systems to gain, or attempt to gain, unauthorized access," according to the latest disclosure. "This has included access to some of the company's source code repositories and internal systems." Microsoft maintains there's "no evidence" so far that the Russian criminals compromised any customer-facing systems. But that's not for lack of trying. "It is apparent that Midnight Blizzard is attempting to use secrets of different types it has found," the Wind...
Microsoft confirms Russian spies stole source code
The Register
·Jessica Lyons
·Published Mar 8, 2024
·Updated
Affected Software
1 affected component
Microsoft Azure
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the confirmation by Microsoft that Russian spies stole source code and gained access to its internal systems.
2
What security implications are discussed in the article?
The ongoing intrusion by Russian cyberspies poses significant risks to Microsoft and its users, potentially compromising sensitive data.
3
What products or software are affected by this breach?
The breach specifically affects Microsoft's Azure platform and other internal systems.
4
How has Microsoft responded to the security breach?
Microsoft characterized the intrusion as ongoing and is actively working to mitigate the effects.
5
What does this incident indicate about the threat landscape?
This incident underscores the persistent threat of state-sponsored cyber espionage targeting major technology companies.