Microsoft: Iran-linked group, dubbed Phosphorus, attempted to hack 241 accounts belonging to a 2020 presidential campaign and others between Aug. and Sept.
This disclosure is the second act in Microsoft's campaign against Phosphorus. Six months earlier, the company said the Iran-linked group had hit 2,200+ people at 200+ companies, stealing secrets and wiping data, and won a US court order to seize 99 Phosphorus-linked websites onto its own servers. The new report shows the group shifting from corporate espionage to political targets: 241 accounts, including one belonging to a 2020 presidential campaign, probed between August and September.
Campaign organizations and political consultants on the targeted account list face immediate credential-theft risk, pushing them toward hardened, monitored email and authentication during the primary season.
Microsoft positions its Threat Intelligence team, fronted by Tom Burt, as the primary public attributor of nation-state election interference — a role that puts its own brand inside the political fight.
Second-order effects
Rival platforms and security vendors face pressure to match Microsoft's public attribution cadence, since campaigns will route communications toward whichever provider names and disrupts the attackers first.
Each Microsoft report becomes citable evidence for later incidents — the 2024 Trump campaign breach was framed through a Microsoft finding — raising the stakes of the company's attribution calls for both victims and accused governments.
Third-order effects
Election security is consolidating around private-sector threat intelligence: a single vendor's telemetry, not government agencies, sets the public narrative on foreign interference, with legal tools like domain seizures becoming a standard countermeasure.
If the Phosphorus pattern holds — corporate espionage expanding into political targeting — Iran's operations become a recurring feature of each US election cycle, forcing campaigns to treat account security as core infrastructure rather than IT hygiene.
The trend: Nation-state hacking of US elections is being surfaced primarily through private-sector attribution, with Microsoft's reports on Iran's Phosphorus group marking the shift from corporate espionage to campaign targeting.
Russia is not the only country interested in swaying the 2020 election. But their success and our failure to harden our democracy has emboldened others. #HandMarkedPaperBallots #ElectionInterference https://www.wired.com/...
One consequence of Russia's successful 2016 election malfeasance: other countries are now trying the same thing. Today we learn that Iran has tried to hack into at least one Presidential campaign. https://www.wired.com/...
A campaign believed to be tied to the Iranian government attempted to identify, attack and breach email addresses belonging to U.S. presidential campaigns, government officials and journalists. Via @greene and @TonyRomm https://www.washingtonpost.com/ ...
#BREAKING Iranians tried to hack U.S. presidential campaign in effort that targeted hundreds, Microsoft says Reuters and other news media outlets report the hackers targeted President Trump's campaign https://www.washingtonpost.com/ ...
Russia doesn't have a monopoly on election hacking. In an aggressive new email phishing push, Microsoft says, Iranian hackers have targeted a US presidential campaign. https://www.wired.com/...
'The aggressiveness of Iran's digital efforts has escalated as its political standing with Washington has worsened, particularly in recent months as President Trump has threatened sanctions over the country's nuclear program.' https://www.washingtonpost.com/ ...
We must create a Cyber “Monroe” doctrine. Policy with teeth to deal with attacks on election/infrastructure/ national interests. U.S. Should lead on this. I introduced legislation early in 115th Congress and would immediately do so again if elected. https://twitter.com/...
Breaking News: Hackers backed by Iran targeted the email accounts of at least one presidential campaign, journalists and U.S. officials, Microsoft said https://www.nytimes.com/...
Who becomes the next US President is critical to the survival of the Islamic Republic, esp as sanctions take their toll and the regime figures out a way to return America to JCPOA https://twitter.com/...
BREAKING: Microsoft says that hackers linked to Iranian government targeted a U.S. presidential campaign, government officials, media targets and prominent expatriate Iranians. https://apnews.com/...
“The targeted accounts are associated with a U.S. presidential campaign, current and former U.S. government officials, journalists covering global politics and prominent Iranians living outside Iran” https://blogs.microsoft.com/ ...
Interesting blog post by @Microsoft. It discloses “significant cyber activity by a threat group we call Phosphorous, which we believe originates from #Iran.” It has targeted accounts associated w/ a 2020 U.S. presidential candidate. https://blogs.microsoft.com/ ...