/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says hackers from Strontium, also known as Fancy Bear/APT28, are targeting 16 global sporting and anti-doping organizations ahead of 2020 Olympics

Microsoft said APT28 targeted “at least 16 national and international sporting and anti-doping organizations.”

ZDNet Catalin Cimpanu

Context & Ripple Effects

This disclosure extends a pattern Microsoft has built over years of publicly naming Fancy Bear's exploitation of a Windows flaw in 2016, its campaign against European research groups and think tanks earlier in 2019, and the blocked attempt to weaponize compromised IoT devices that summer. Each report has positioned Microsoft as one of the few private companies willing to attribute Russian state-linked operations by name.

The shift here is the target set: rather than policy institutes or infrastructure, Strontium is now aiming at sporting and anti-doping bodies on the eve of the 2020 Tokyo Games, where doping disputes and athlete eligibility are politically charged. Microsoft's later court-ordered seizure of seven Strontium domains shows this attribution work escalating into active disruption.

First-order effects

  • At least 16 national and international sporting and anti-doping organizations face immediate credential-harvesting and intrusion risk heading into the 2020 Olympics, forcing security reviews weeks before the Games.
  • Microsoft's Threat Intelligence team gains another public attribution win, reinforcing its role as the primary private-sector channel for exposing Strontium operations.

Second-order effects

  • Olympic organizers and national cybersecurity agencies come under pressure to coordinate defenses with Microsoft around the Games, since the targeting list spans multiple countries' sporting bodies.
  • Other technology vendors face expectations to match Microsoft's disclosure cadence, turning threat-intelligence transparency into a competitive differentiator rather than an anomaly.

Third-order effects

  • If the sequence holds — attribution, then legal action like the domain seizures — private companies increasingly function as a counterintelligence layer between states, normalizing corporate naming-and-shaming of nation-state hackers as standard practice.
  • Major global events like the Olympics become recurring targets for intelligence collection around politically sensitive data such as anti-doping records, pushing event organizers to treat cyber threats as core event infrastructure.

The trend: Microsoft is consolidating into a de facto public attribution and disruption force against Strontium, moving from reporting intrusions to legally dismantling the group's infrastructure.

Discussion

  • @rodrosenstein Rod Rosenstein on x
    “We think it's critical that governments and the private sector are increasingly transparent about nation-state activity so we can all continue the global dialogue about protecting the internet.... You can protect yourself from these types of attacks.” https://blogs.microsoft.com…
  • @florencebonnet Florence Bonnet on x
    New cyberattacks targeting sporting and anti-doping organizations : spear-phishing, password spray, attacks against IoT, open-source and custom malware https://blogs.microsoft.com/ ... #cybersecurity
  • @jeffstone500 Jeff Stone on x
    Microsoft just said the Russian hacking group Fancy Bear targeted at least 16 athletic organizations ahead of the Tokyo Olympics. The timing of this announcement roughly coincides with a years-long ban of two Russian athletes from competition. https://www.cyberscoop.com/...
  • @reuters @reuters on x
    Microsoft says it has tracked ‘significant’ cyberattacks coming from a group it calls ‘Strontium’ or ‘Fancy Bear’ that targeted anti-doping authorities and global sporting organizations https://www.reuters.com/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Microsoft said APT28 has targeted “at least 16 national and international sporting and anti-doping organizations across three continents” ahead of next year's Tokyo Olympics Attacks come after WADA started mulling another ban on Russian athletes. https://www.zdnet.com/... https:/…
  • @olivia_gazis Olivia Gazis on x
    Microsoft's @TomBurt45 said the company notified 16 sporting/anti-doping orgs about “significant cyberattacks” originating from a group linked to Russia ahead of the 2020 Tokyo Summer Olympic Games. “[T]he majority” were unsuccessful, Microsoft said. https://blogs.microsoft.com/ …
  • @kevincollier Kevin Collier on x
    Forever fascinated by GRU taking time off their election interference in 2016 to hack @wada_ama & falsely accuse Simone Biles and the Williams sisters of cheating like the Russians did. And the IOC deciding that didn't warrant extra punishment for Russia. https://blogs.microsoft.…