/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft: Iran-linked group, dubbed Phosphorus, attempted to hack 241 accounts belonging to a 2020 presidential campaign and others between Aug. and Sept.

Tom Burt / Microsoft on the Issues :

Microsoft on the Issues Tom Burt

Context & Ripple Effects

This disclosure is the second act in Microsoft's campaign against Phosphorus. Six months earlier, the company said the Iran-linked group had hit 2,200+ people at 200+ companies, stealing secrets and wiping data, and won a US court order to seize 99 Phosphorus-linked websites onto its own servers. The new report shows the group shifting from corporate espionage to political targets: 241 accounts, including one belonging to a 2020 presidential campaign, probed between August and September.

The report also establishes the reporting template Microsoft would reuse: in 2020 it flagged escalating Russian, Chinese, and Iranian attacks on election participants, and in 2024 the Trump campaign cited a Microsoft report on Iranian spear phishing when it confirmed its internal communications were hacked. Tom Burt's disclosure is the earliest data point in that arc.

First-order effects

  • Campaign organizations and political consultants on the targeted account list face immediate credential-theft risk, pushing them toward hardened, monitored email and authentication during the primary season.
  • Microsoft positions its Threat Intelligence team, fronted by Tom Burt, as the primary public attributor of nation-state election interference — a role that puts its own brand inside the political fight.

Second-order effects

  • Rival platforms and security vendors face pressure to match Microsoft's public attribution cadence, since campaigns will route communications toward whichever provider names and disrupts the attackers first.
  • Each Microsoft report becomes citable evidence for later incidents — the 2024 Trump campaign breach was framed through a Microsoft finding — raising the stakes of the company's attribution calls for both victims and accused governments.

Third-order effects

  • Election security is consolidating around private-sector threat intelligence: a single vendor's telemetry, not government agencies, sets the public narrative on foreign interference, with legal tools like domain seizures becoming a standard countermeasure.
  • If the Phosphorus pattern holds — corporate espionage expanding into political targeting — Iran's operations become a recurring feature of each US election cycle, forcing campaigns to treat account security as core infrastructure rather than IT hygiene.

The trend: Nation-state hacking of US elections is being surfaced primarily through private-sector attribution, with Microsoft's reports on Iran's Phosphorus group marking the shift from corporate espionage to campaign targeting.

Discussion

  • @wildpalmsltd @wildpalmsltd on x
    Russia is not the only country interested in swaying the 2020 election. But their success and our failure to harden our democracy has emboldened others. #HandMarkedPaperBallots #ElectionInterference https://www.wired.com/...
  • @shadowingtrump Shadow Cabinet on x
    Hmm, here come the Iranians. Where did they get the idea of manipulating our elections? https://www.washingtonpost.com/ ... https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    BREAKING: The candidate Iranian hackers targeted? Microsoft will not say but sources confirm it was @realDonaldTrump's. https://twitter.com/...
  • @nxthompson Nicholas Thompson on x
    One consequence of Russia's successful 2016 election malfeasance: other countries are now trying the same thing. Today we learn that Iran has tried to hack into at least one Presidential campaign. https://www.wired.com/...
  • @posttech @posttech on x
    A campaign believed to be tied to the Iranian government attempted to identify, attack and breach email addresses belonging to U.S. presidential campaigns, government officials and journalists. Via @greene and @TonyRomm https://www.washingtonpost.com/ ...
  • @hawaiidelilah @hawaiidelilah on x
    Will be interesting to see if Republicans thinks this is very legal and very cool. https://twitter.com/...
  • @natashafatah Natasha Fatah on x
    #BREAKING Iranians tried to hack U.S. presidential campaign in effort that targeted hundreds, Microsoft says Reuters and other news media outlets report the hackers targeted President Trump's campaign https://www.washingtonpost.com/ ...
  • @sheistenacious True Blue on x
    Seems like a good time to beef up election security. Isn't that right #MoscowMitch ? #DemForce https://twitter.com/...
  • @wired @wired on x
    Russia doesn't have a monopoly on election hacking. In an aggressive new email phishing push, Microsoft says, Iranian hackers have targeted a US presidential campaign. https://www.wired.com/...
  • @adegrandpre Andrew deGrandpre on x
    'The aggressiveness of Iran's digital efforts has escalated as its political standing with Washington has worsened, particularly in recent months as President Trump has threatened sanctions over the country's nuclear program.' https://www.washingtonpost.com/ ...
  • @scotttaylorva Scott Taylor on x
    We must create a Cyber “Monroe” doctrine. Policy with teeth to deal with attacks on election/infrastructure/ national interests. U.S. Should lead on this. I introduced legislation early in 115th Congress and would immediately do so again if elected. https://twitter.com/...
  • @nytimes @nytimes on x
    Breaking News: Hackers backed by Iran targeted the email accounts of at least one presidential campaign, journalists and U.S. officials, Microsoft said https://www.nytimes.com/...
  • @alirezanader Alireza Nader on x
    Who becomes the next US President is critical to the survival of the Islamic Republic, esp as sanctions take their toll and the regime figures out a way to return America to JCPOA https://twitter.com/...
  • @politicalmiller Jack Miller on x
    We have a president who won't lift a finger to protect American democracy. And now our enemies know it too. https://twitter.com/...
  • @ap @ap on x
    BREAKING: Microsoft says that hackers linked to Iranian government targeted a U.S. presidential campaign, government officials, media targets and prominent expatriate Iranians. https://apnews.com/...
  • @wajahatali Wajahat Ali on x
    Well, when Trump invites foreign interference... https://www.nytimes.com/...
  • @washingtonpost @washingtonpost on x
    Microsoft linked the hacking campaign to Iran's government but did not identify the targets https://www.washingtonpost.com/ ...
  • @bing_chris Chris Bing on x
    “The targeted accounts are associated with a U.S. presidential campaign, current and former U.S. government officials, journalists covering global politics and prominent Iranians living outside Iran” https://blogs.microsoft.com/ ...
  • @jasonmbrodsky Jason Brodsky on x
    Interesting blog post by @Microsoft. It discloses “significant cyber activity by a threat group we call Phosphorous, which we believe originates from #Iran.” It has targeted accounts associated w/ a 2020 U.S. presidential candidate. https://blogs.microsoft.com/ ...