Russian hackers compromised Microsoft cloud customers through third party, putting emails and other data at risk
Summary
“If it’s true that a cloud service provider customer’s data has been exfiltrated and is in the hands of some threat actor, that’s a very serious situation,” said John Reed Stark, who runs a consulting firm and is former chief of the Securities and Exchange Commission’s Office of Internet Enforcement. “It should raise all sorts of alerts within that cloud provider that could trigger a litany of notification, remediation and disclosure requirements — both national and international.” Microsoft itself has not publicly announced the reseller hack. In September, a federal judge denied Amazon’s motion to dismiss, saying its “negligent conduct” probably “made the attack possible.” The investigation has now become the top priority for Gen. Paul Nakasone, who heads both the National Security Agency and the military’s U.S. Cyber Command. Developing a coherent, unified picture of the extent of the breaches has been difficult because neither the NSA nor the Department of Homeland Security nor the FBI has the legal or jurisdictional authority to know where all the compromises are. U.S. government and private-sector sources now say the total number of victims — of agencies and companies that have seen data stolen — is likely to be at most in the low hundreds, not in the thousands as previously feared.