Hackers hit Microsoft’s customer support system, run away with data

[ad_1]

James Martin / CNET

Microsoft said on Friday that hackers hacked into a computer used by one of its customer service agents and stole account data which they then used to launch “highly targeted” attacks on customers. The company identified the hacker group as Nobelium, the same person responsible for last year’s major SolarWinds breach.

Microsoft protected the computer, which hackers infected with information-stealing software, and informed the “small number” of affected customers, it said in a post Friday on its Security Response Center site.

The company sent a notice to affected Microsoft service subscribers saying the hackers gained access to the information during the second half of May, Reuters reported late Friday. The stolen data included contact information for billing and the services customers pay for, the store said. Hackers can use this basic data in bogus emails and phone calls as part of phishing attacks that can help them gain access to more sensitive information.

Microsoft warned affected customers to pay attention to communications with billing contacts and suggested that changing passwords and related usernames might be a good idea, Reuters reported. The company also urged customers to use multi-factor authentication to protect themselves from hacks. Microsoft’s investigation into the breach is ongoing and has not yet found that any customers have been successfully compromised.

The tech giant said it discovered the breach while examining new assets from the Nobelium group. He said just over half of that activity was aimed at information technology companies, followed by government agencies and then a small percentage of non-governmental agencies, think tanks and financial services firms.

SolarWinds hacking campaign made headlines in December 2020. It used corrupt software from IT management company SolarWinds, along with other hacking methods, to hack thousands of organizations and dig deeper into at least nine federal agencies and 100 private companies , including Microsoft.

Microsoft has made no further comment on the customer service breach, aside from its blog post.

Learn more: SolarWinds hacker: what you need to know

If you sign up for just one CNET newsletter, that’s it. Get top picks from editors of the hottest reviews, news and videos of the day.

[ad_2]

picture credit

Related Posts