Technology

CISA Confirms Russian Government-Backed Hackers Stole U.S. Federal Agency Emails

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has verified that Russian government-backed hackers infiltrated several U.S. federal agencies' emails as a consequence of an ongoing cyberattack targeting Microsoft. In a statement released on Thursday, CISA disclosed that the cyberattack, initially disclosed by Microsoft in January, enabled hackers to pilfer federal government emails "through a

CISA Confirms Russian Government-Backed Hackers Stole U.S. Federal Agency Emails

CISA Confirms Russian Government-Backed Hackers Stole U.S. Federal Agency Emails

Share
Picture: Bleeping Computer
Advertisement

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has verified that Russian government-backed hackers infiltrated several U.S. federal agencies’ emails as a consequence of an ongoing cyberattack targeting Microsoft.

In a statement released on Thursday, CISA disclosed that the cyberattack, initially disclosed by Microsoft in January, enabled hackers to pilfer federal government emails “through a successful compromise of Microsoft corporate email accounts.”

Referred to as “Midnight Blizzard” by Microsoft and also known as APT29, the hackers are widely believed to operate under Russia’s Foreign Intelligence Service, or SVR.

CISA expressed grave concern over Midnight Blizzard’s breach of Microsoft corporate email accounts and the subsequent extraction of correspondence between agencies and Microsoft, deeming it an “unacceptable risk” to agencies.

On April 2, CISA issued a new emergency directive instructing civilian government agencies to bolster the security of their email accounts in response to fresh intelligence indicating heightened intrusion activities by Russian hackers. After granting affected federal agencies a week to reset passwords and fortify compromised systems, CISA made the details of the emergency directive public on Thursday.

While CISA refrained from naming the specific federal agencies affected by the email theft, a spokesperson for the agency declined to provide immediate comment when approached by TechCrunch.

Reports of the emergency directive surfaced last week, initially disclosed by Cyberscoop.

This emergency directive coincides with mounting scrutiny of Microsoft’s security practices following a series of intrusions by adversarial nation-state hackers. The U.S. government heavily relies on Microsoft for hosting government email accounts.

Microsoft publicly acknowledged in January that the Russian hacking group breached certain corporate email systems, including accounts belonging to “senior leadership team and employees in our cybersecurity, legal, and other functions.” The hackers sought information about Microsoft’s knowledge of their activities. Subsequently, Microsoft revealed that the hackers targeted entities beyond Microsoft.

It is now evident that some of the affected organizations included U.S. government agencies.

As of March, Microsoft continued efforts to expel the Russian hackers from its systems in what it described as an “ongoing attack.” The company reported that the hackers aimed to leverage pilfered “secrets” to access additional internal Microsoft systems and extract more data, including source code.

TechnologyAfrican startups
Greg Stewart

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Africa is getting more Big Tech investment, but the basics are still holding it back
Read nextTechnology

Africa is getting more Big Tech investment, but the basics are still holding it back

Google, Meta, Microsoft, Amazon and Starlink are putting more money into Africa's digital infrastructure. Subsea cables are reaching more parts of the continent, satellite internet is expanding and cloud companies are adding services for African customers. For businesses that have spent years dealing with unreliable connections, that is useful. There is still a problem underneath

Vutomi Manzini · 4 min readContinue reading