Microsoft says an attacker gained access to one of its customer service agents and launched attacks against customers in a probe of suspected SolarWinds hackers
Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information …
Context & Ripple Effects
The suspected SolarWinds activity had already reached Microsoft itself: attackers accessed an employee account and viewed some source code without modifying it or accessing email, according to Microsoft's earlier account of the source-code exposure. Related coverage also described a later campaign using a seized U.S. aid-agency email system to send malicious code to 150 organizations.
The newly reported customer-facing misuse broadens the arc from intrusion into Microsoft systems to use of trusted Microsoft-held information against customers. It follows the aid-agency email campaign in showing how compromised access can be turned into a channel for reaching downstream targets.
First-order effects
- Microsoft's affected customers face attacks launched with information available through a compromised customer-service agent, while Microsoft must investigate the agent-access path as part of its SolarWinds probe.
- Customer-service operations become an immediate security boundary for Microsoft, rather than only a support function.
Second-order effects
- Organizations that interact with Microsoft support have reason to scrutinize support-related outreach and account information as potential inputs to targeted attacks.
- The incident extends the operational burden of the SolarWinds response from protecting Microsoft’s internal code and email environments to protecting the customer relationships handled by support staff.
Third-order effects
- The pattern points to supply-chain and identity incidents being judged not only by what attackers enter, but by which trusted business channels they can repurpose to reach downstream organizations.
- If repeated, breaches of support and administrative access will push enterprise security programs to treat customer-facing operational roles as high-value attack paths alongside engineering and email systems.
The trend: SolarWinds-related reporting is tracing a shift from access to major vendors’ internal systems toward abuse of the trusted channels those vendors use to reach customers and partner organizations.