/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says an attacker gained access to one of its customer service agents and launched attacks against customers in a probe of suspected SolarWinds hackers

The Microsoft Threat Intelligence Center is tracking new activity from the NOBELIUM threat actor. Tom Warren / The Verge : Why Windows 11 is forcing everyone to use TPM chips Malcolm Owen / AppleInsider : SolarWinds hackers stole data from Microsoft's customer support system Mariella Moon / Engadget : Microsoft customer support rep compromised by hackers behind SolarWinds breach Lawrence Abrams / BleepingComputer : Nobelium hackers accessed Microsoft customer support tools Pierluigi Paganini / Security Affairs : Microsoft: Russia-linked SolarWinds hackers breached three new entities Nathaniel Mott / PCMag : Microsoft Warns of Continued Attacks by the Nobelium Hacking Group Usama Jawad / Neowin : Microsoft issues advisory about new cyberattack targeting IT and government organizations Catalin Cimpanu / The Record : Microsoft says SolarWinds hacking group has breached three new victims Robert McMillan / Wall Street Journal : Microsoft Discloses New Customer Hack Linked to SolarWinds Cyberattackers Alyse Stanley / Gizmodo : Microsoft Says SolarWinds Hackers Exploited Its Own Customer Support Tools Margaret Harding McGill / Axios : Microsoft sees targeted attacks from Russia-based group Iain Thomson / The Register : SolarWinds backdoor gang pwns Microsoft support agent to turn sights on customers Mitchell Clark / The Verge : Microsoft says its customer support tools were compromised by the SolarWinds hackers Kartikay Mehrotra / Bloomberg : Microsoft Says SolarWinds Hackers Attacked Three in New Breach Tweets: Joseph Menn / @josephmenn : Adds comment from White House and CISA. https://www.reuters.com/... Michael MacKay / @mhmck : Another act of war by aggressor Russia against Western democracies - the “Nobelium” cyber warfare unit has struck the United States, the United Kingdom, Canada, Germany and 32 other countries. #PutinAtWar https://msrc-blog.microsoft.com/ ... Thaddeus E. Grugq / @thegrugq : Reading what is said literally here, “Zero Trust didn't help protect our customers at all. In no way did Zero Trust prevent the threat actors from accessing and abusing privileged customer information as part of their broader campaign.” Not sure why they added that. https://twitter.com/... Adam Levin / @adam_k_levin : The question remains: how many more breaches are out there that haven't been discovered yet? https://www.reuters.com/... Dave Kennedy / @hackingdave : Yikes. Fascinating read with hopefully more details coming out soon: “Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.” https://twitter.com/... Hakan / @hatr : „When Reuters asked about that warning, Microsoft announced the breach publicly" https://www.reuters.com/... Joseph Menn / @josephmenn : It's kind of like when Steve Jobs would say, oh, and there's one more thing. Only also the opposite of that. https://twitter.com/... @jfslowik : Man, some ACTUAL DETAILS would be nice here... https://msrc-blog.microsoft.com/ ... Jake Williams / @malwarejake : Nobelium (the same threat actor that compromised #SolarWinds) also compromised a Microsoft support agent. I suspect this is going to become a case study for the efficacy of Zero-Trust (and rightfully so). https://msrc-blog.microsoft.com/ ... https://twitter.com/... Joseph Menn / @josephmenn : This is separate from an earlier breach of Microsoft by the same group, in which the suspected Russian attackers took software code for managing user identities.

Reuters Joseph Menn

Context & Ripple Effects

Microsoft’s exposure to the suspected SolarWinds-linked group had already extended beyond its software supply chain: attackers had viewed some source code through a compromised employee account, though Microsoft said they could not alter code or reach email in the earlier source-code exposure.

The group also used a seized State Department aid-agency email system to send malicious code to roughly 150 organizations. The newly identified use of a Microsoft support credential shows the campaign moving through trusted service relationships as well as email systems.

First-order effects

  • Microsoft customers targeted through the compromised support agent face attacks originating from a channel that ordinarily carries administrative trust, while Microsoft must contain the agent’s access and notify affected customers.
  • Microsoft’s Threat Intelligence Center is treating the activity as a new NOBELIUM campaign and has issued an advisory focused on IT and government targets.

Second-order effects

  • Organizations using Microsoft support must treat support interactions and agent-mediated access as part of their security perimeter, alongside the email channels exploited in the aid-agency phishing campaign.
  • Microsoft’s support operation becomes a security-control point: the value of an agent credential to attackers raises pressure to narrow and monitor the customer access available through support workflows.

Third-order effects

  • The sequence points to a broader attack-surface shift in which trusted operational identities—employee, support, and service accounts—can provide a route to many downstream organizations.
  • If repeated, supplier and enterprise security programs will increasingly evaluate not only product code and email defenses but also the privileged human workflows connecting vendors to customers.

The trend: SolarWinds-linked activity is illustrating how compromise of trusted service identities can turn a single vendor access point into a customer-targeting channel.

Discussion

  • @thegrugq Thaddeus E. Grugq on x
    Reading what is said literally here, “Zero Trust didn't help protect our customers at all. In no way did Zero Trust prevent the threat actors from accessing and abusing privileged customer information as part of their broader campaign.” Not sure why they added that. https://twitt…
  • @josephmenn Joseph Menn on x
    Adds comment from White House and CISA. https://www.reuters.com/...
  • @mhmck Michael MacKay on x
    Another act of war by aggressor Russia against Western democracies - the “Nobelium” cyber warfare unit has struck the United States, the United Kingdom, Canada, Germany and 32 other countries. #PutinAtWar https://msrc-blog.microsoft.com/ ...
  • @adam_k_levin Adam Levin on x
    The question remains: how many more breaches are out there that haven't been discovered yet? https://www.reuters.com/...
  • @hackingdave Dave Kennedy on x
    Yikes. Fascinating read with hopefully more details coming out soon: “Microsoft (MSFT.O) said on Friday an attacker had won access to one of its customer-service agents and then used information from that to launch hacking attempts against customers.” https://twitter.com/...
  • @hatr Hakan on x
    „When Reuters asked about that warning, Microsoft announced the breach publicly" https://www.reuters.com/...
  • @josephmenn Joseph Menn on x
    It's kind of like when Steve Jobs would say, oh, and there's one more thing. Only also the opposite of that. https://twitter.com/...
  • @jfslowik @jfslowik on x
    Man, some ACTUAL DETAILS would be nice here... https://msrc-blog.microsoft.com/ ...
  • @malwarejake Jake Williams on x
    Nobelium (the same threat actor that compromised #SolarWinds) also compromised a Microsoft support agent. I suspect this is going to become a case study for the efficacy of Zero-Trust (and rightfully so). https://msrc-blog.microsoft.com/ ... https://twitter.com/...
  • @josephmenn Joseph Menn on x
    This is separate from an earlier breach of Microsoft by the same group, in which the suspected Russian attackers took software code for managing user identities.