/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft, following a probe of SolarWinds hack, says an attacker compromised one of the company's support agents to launch attacks against customers

Reuters Joseph Menn

Context & Ripple Effects

Microsoft’s SolarWinds investigation had already found that intruders viewed some source code through an employee account without modifying code or accessing email. The new finding shifts the relevant exposure from Microsoft’s internal development environment to a customer-facing support workflow.

Microsoft had also identified more than 40 customers targeted in the broader SolarWinds incident and called the attack ongoing. Compromise of a support agent supplies a concrete route by which attackers could extend access toward customers.

First-order effects

  • Customers targeted through the compromised support-agent access face an immediate incident-response and account-security problem alongside Microsoft’s own investigation.
  • Microsoft must treat support-agent access as a privileged security boundary, not only an internal customer-service function.

Second-order effects

  • The finding broadens the practical scope of the SolarWinds response: customer-facing operational accounts now require the same scrutiny as the employee account involved in the earlier source-code exposure.
  • Microsoft customers will have reason to verify support-channel interactions and access associated with the affected workflow, increasing the operational burden of the investigation.

Third-order effects

  • The episode points to a wider security shift in which trusted vendor staff and support systems become consequential pathways into customer environments, alongside compromised software and employee accounts.

The trend: SolarWinds-related investigations are revealing how attacks can traverse multiple trust layers, from employee credentials and software ecosystems to customer-support operations.

Discussion

  • @mhmck Michael MacKay on x
    Another act of war by aggressor Russia against Western democracies - the “Nobelium” cyber warfare unit has struck the United States, the United Kingdom, Canada, Germany and 32 other countries. #PutinAtWar https://msrc-blog.microsoft.com/ ...
  • @josephmenn Joseph Menn on x
    Adds comment from White House and CISA. https://www.reuters.com/...
  • @thegrugq Thaddeus E. Grugq on x
    Reading what is said literally here, “Zero Trust didn't help protect our customers at all. In no way did Zero Trust prevent the threat actors from accessing and abusing privileged customer information as part of their broader campaign.” Not sure why they added that. https://twitt…
  • @adam_k_levin Adam Levin on x
    The question remains: how many more breaches are out there that haven't been discovered yet? https://www.reuters.com/...
  • @hackingdave Dave Kennedy on x
    Yikes. Fascinating read with hopefully more details coming out soon: “Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.” https://twitter.com/...
  • @hatr Hakan on x
    „When Reuters asked about that warning, Microsoft announced the breach publicly" https://www.reuters.com/...
  • @malwarejake Jake Williams on x
    Nobelium (the same threat actor that compromised #SolarWinds) also compromised a Microsoft support agent. I suspect this is going to become a case study for the efficacy of Zero-Trust (and rightfully so). https://msrc-blog.microsoft.com/ ... https://twitter.com/...
  • @josephmenn Joseph Menn on x
    It's kind of like when Steve Jobs would say, oh, and there's one more thing. Only also the opposite of that. https://twitter.com/...
  • @jfslowik @jfslowik on x
    Man, some ACTUAL DETAILS would be nice here... https://msrc-blog.microsoft.com/ ...
  • @josephmenn Joseph Menn on x
    This is separate from an earlier breach of Microsoft by the same group, in which the suspected Russian attackers took software code for managing user identities.