Microsoft says an attacker gained access to one of its customer service agents and launched attacks against customers in a probe of suspected SolarWinds hackers
The Microsoft Threat Intelligence Center is tracking new activity from the NOBELIUM threat actor. Tom Warren / The Verge : Why Windows 11 is forcing everyone to use TPM chips Malcolm Owen / AppleInsider : SolarWinds hackers stole data from Microsoft's customer support system Mariella Moon / Engadget : Microsoft customer support rep compromised by hackers behind SolarWinds breach Lawrence Abrams / BleepingComputer : Nobelium hackers accessed Microsoft customer support tools Pierluigi Paganini / Security Affairs : Microsoft: Russia-linked SolarWinds hackers breached three new entities Nathaniel Mott / PCMag : Microsoft Warns of Continued Attacks by the Nobelium Hacking Group Usama Jawad / Neowin : Microsoft issues advisory about new cyberattack targeting IT and government organizations Catalin Cimpanu / The Record : Microsoft says SolarWinds hacking group has breached three new victims Robert McMillan / Wall Street Journal : Microsoft Discloses New Customer Hack Linked to SolarWinds Cyberattackers Alyse Stanley / Gizmodo : Microsoft Says SolarWinds Hackers Exploited Its Own Customer Support Tools Margaret Harding McGill / Axios : Microsoft sees targeted attacks from Russia-based group Iain Thomson / The Register : SolarWinds backdoor gang pwns Microsoft support agent to turn sights on customers Mitchell Clark / The Verge : Microsoft says its customer support tools were compromised by the SolarWinds hackers Kartikay Mehrotra / Bloomberg : Microsoft Says SolarWinds Hackers Attacked Three in New Breach Tweets: Joseph Menn / @josephmenn : Adds comment from White House and CISA. https://www.reuters.com/... Michael MacKay / @mhmck : Another act of war by aggressor Russia against Western democracies - the “Nobelium” cyber warfare unit has struck the United States, the United Kingdom, Canada, Germany and 32 other countries. #PutinAtWar https://msrc-blog.microsoft.com/ ... Thaddeus E. Grugq / @thegrugq : Reading what is said literally here, “Zero Trust didn't help protect our customers at all. In no way did Zero Trust prevent the threat actors from accessing and abusing privileged customer information as part of their broader campaign.” Not sure why they added that. https://twitter.com/... Adam Levin / @adam_k_levin : The question remains: how many more breaches are out there that haven't been discovered yet? https://www.reuters.com/... Dave Kennedy / @hackingdave : Yikes. Fascinating read with hopefully more details coming out soon: “Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.” https://twitter.com/... Hakan / @hatr : „When Reuters asked about that warning, Microsoft announced the breach publicly" https://www.reuters.com/... Joseph Menn / @josephmenn : It's kind of like when Steve Jobs would say, oh, and there's one more thing. Only also the opposite of that. https://twitter.com/... @jfslowik : Man, some ACTUAL DETAILS would be nice here... https://msrc-blog.microsoft.com/ ... Jake Williams / @malwarejake : Nobelium (the same threat actor that compromised #SolarWinds) also compromised a Microsoft support agent. I suspect this is going to become a case study for the efficacy of Zero-Trust (and rightfully so). https://msrc-blog.microsoft.com/ ... https://twitter.com/... Joseph Menn / @josephmenn : This is separate from an earlier breach of Microsoft by the same group, in which the suspected Russian attackers took software code for managing user identities.
Context & Ripple Effects
Microsoft’s exposure to the suspected SolarWinds-linked group had already extended beyond its software supply chain: attackers had viewed some source code through a compromised employee account, though Microsoft said they could not alter code or reach email in the earlier source-code exposure.
The group also used a seized State Department aid-agency email system to send malicious code to roughly 150 organizations. The newly identified use of a Microsoft support credential shows the campaign moving through trusted service relationships as well as email systems.
First-order effects
- Microsoft customers targeted through the compromised support agent face attacks originating from a channel that ordinarily carries administrative trust, while Microsoft must contain the agent’s access and notify affected customers.
- Microsoft’s Threat Intelligence Center is treating the activity as a new NOBELIUM campaign and has issued an advisory focused on IT and government targets.
Second-order effects
- Organizations using Microsoft support must treat support interactions and agent-mediated access as part of their security perimeter, alongside the email channels exploited in the aid-agency phishing campaign.
- Microsoft’s support operation becomes a security-control point: the value of an agent credential to attackers raises pressure to narrow and monitor the customer access available through support workflows.
Third-order effects
- The sequence points to a broader attack-surface shift in which trusted operational identities—employee, support, and service accounts—can provide a route to many downstream organizations.
- If repeated, supplier and enterprise security programs will increasingly evaluate not only product code and email defenses but also the privileged human workflows connecting vendors to customers.
The trend: SolarWinds-linked activity is illustrating how compromise of trusted service identities can turn a single vendor access point into a customer-targeting channel.