Microsoft, following a probe of SolarWinds hack, says an attacker compromised one of the company's support agents to launch attacks against customers
ReutersJoseph Menn
Context & Ripple Effects
Microsoft’s SolarWinds investigation had already found that intruders viewed some source code through an employee account without modifying code or accessing email. The new finding shifts the relevant exposure from Microsoft’s internal development environment to a customer-facing support workflow.
Customers targeted through the compromised support-agent access face an immediate incident-response and account-security problem alongside Microsoft’s own investigation.
Microsoft must treat support-agent access as a privileged security boundary, not only an internal customer-service function.
Second-order effects
The finding broadens the practical scope of the SolarWinds response: customer-facing operational accounts now require the same scrutiny as the employee account involved in the earlier source-code exposure.
Microsoft customers will have reason to verify support-channel interactions and access associated with the affected workflow, increasing the operational burden of the investigation.
Third-order effects
The episode points to a wider security shift in which trusted vendor staff and support systems become consequential pathways into customer environments, alongside compromised software and employee accounts.
The trend: SolarWinds-related investigations are revealing how attacks can traverse multiple trust layers, from employee credentials and software ecosystems to customer-support operations.
Another act of war by aggressor Russia against Western democracies - the “Nobelium” cyber warfare unit has struck the United States, the United Kingdom, Canada, Germany and 32 other countries. #PutinAtWar https://msrc-blog.microsoft.com/ ...
Reading what is said literally here, “Zero Trust didn't help protect our customers at all. In no way did Zero Trust prevent the threat actors from accessing and abusing privileged customer information as part of their broader campaign.” Not sure why they added that. https://twitt…
Yikes. Fascinating read with hopefully more details coming out soon: “Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.” https://twitter.com/...
Nobelium (the same threat actor that compromised #SolarWinds) also compromised a Microsoft support agent. I suspect this is going to become a case study for the efficacy of Zero-Trust (and rightfully so). https://msrc-blog.microsoft.com/ ... https://twitter.com/...
This is separate from an earlier breach of Microsoft by the same group, in which the suspected Russian attackers took software code for managing user identities.