
The United States Cybersecurity and Infrastructure Security Agency (CISA), in fresh claims, said that their access to the email system of Microsoft was misused by Russian government-backed hackers to steal correspondence between the tech giant and officials.
The new claims were made in an emergency directive which was issued by the US watchdog on Thursday (April 11).
The agency, in its directive which was dated April 2, issued a warning that the authentication details shared by Microsoft email are being exploited by hackers to gain entry into the customer systems of Microsoft, which included the systems of some unspecified number of government agencies.
Speaking to the reporters, US Cybersecurity and Infrastructure Security Agency (CISA) senior official Eric Goldstein said that “several” US federal agencies have been notified by Microsoft about the possibility of hackers stealing their emails by getting access to login information like usernames, or passwords.
Also Read:North Korean hackers broke into South Korean chip equipment firms: Seoul
“At this time, we are not aware of any agency production environments that have experienced a compromise as a result of a credential exposure,” said Goldstein.
The US watchdog's warning that the stolen Microsoft emails are being used to target government agencies follows the announcement made by the company in March that it was still dealing with the intruders, who had been nicknamed "Midnight Blizzard."
An “emergency directive” was publicly released by CISA on Thursday (April 11) which gave orders to civilian agencies, which were likely to be affected by the hacking campaign, to increase their defences.
CISA said that the potential leak of agency login credentials is an “unacceptable risk to agencies.”
In an email, Microsoft said that it was "working with our customers to help them investigate and mitigate. This includes working with CISA on an emergency directive to provide guidance to government agencies."
Speaking to CNN on Thursday (April 11), a Microsoft spokesperson said, “As we shared in our March 8 blog, as we discover secrets in our exfiltrated email, we are working with our customers to help them investigate and mitigate. This includes working with CISA on an emergency directive to provide guidance to government agencies.”
Watch:Who is behind hacking operation against US and UK?
Last week, the US Cyber Safety Review Board submitted a report in which China was blamed for a separate hack. It was said that the hack was preventable and it was a result of a deliberate lack of transparency and cybersecurity lapses.
CISA further said that the hackers may have tried to attack other non-governmental groups as well. "Other organisations may also have been impacted by the exfiltration of Microsoft corporate email," said CISA.
(With inputs from agencies)