Home Blog Page 323

Symantec joins DoD’s Defense Industrial Base Cybersecurity program

Symantec

Cybersecurity company Symantec announced it has become a member of the United States’ Department of Defense’s (DOD) Defense Industrial Base (DIB) Cybersecurity (CS) program. The DIB CS program is a voluntary cyber threat information-sharing initiative established by the DOD to enhance and supplement DIB participants’ capabilities to mitigate cyber attacks. The program features a collaborative information-sharing environment where members voluntarily report cyber threats as well as information on how to prevent/mitigate those threats.

“This is a prime example of an effective government-industry collaborative partnership. Symantec is proud to work in conjunction with the DOD and its partners to deliver a stronger cyber environment,” said Chris Townsend, Symantec vice president of federal. “The DIB CS program provides an important platform to share threat information and best practices, helping to improve the overall cyber awareness and security posture of all members. Symantec is proud to become a member of this important community.”

Symantec is supporting the mission of the DOD against cyber adversaries by working collaboratively to enhance the security posture of the United States. DIB CS industry partners can benefit from Symantec’s array of cybersecurity capabilities to enable compliance with the mandates of the National Institute of Standards and Technology’s (NIST) SP 800-171. NIST SP 800-171 establishes a set of security requirements for protecting Controlled Unclassified Information (CUI) stored in nonfederal systems and organizations.

Symantec’s Global Intelligence Network is one of the world’s largest threat intelligence networks, composed of threat data from 175 million protected endpoints and 123 million attack sensors worldwide collecting billions of cyber threat telemetry vectors daily.

 

WannaCry hero pleads guilty for helping distribute malware

WannaCry-wakeup-call

British cybersecurity researcher Marcus Hutchens alias MalwareTech, the WannaCry savior has pleaded guilty to the charges pressed against him for the sale of Kronos and UPAS-Kit malware online between 2012 and 2015. It was also notified that Hutchens once himself delivered kit to someone in California. According to procecutors, the kits were used to intercept communications and collect personal information, including usernames, passwords, email addresses, and financial data from computers and was used to infect numerous computers around the world and steal banking information.

Hutchens is the same security expert who discovered the killswitch for devasting WannaCry cyberattack that jolted the world in 2017. Ever since then, he has been revered as a hero among the infosec community worldwide as he had successfully prevented the world from becoming hostage to cyber criminals. The trial has struck a nerve of several information security experts.

Hutchens confirmed the plea. “As you may be aware, I’ve pleaded guilty to two charges related to writing malware in the years prior to my career in security,” Hutchins said in a statement on his website. “I regret these actions and accept full responsibility for my mistakes. Having grown up, I’ve since been using the same skills that I misused several years ago for constructive purposes. I will continue to devote my time to keeping people safe from malware attacks.”

Hutchens has pleaded guilty to two charges while six charges against him have been dropped. Each of the charges carries a sentence of five years in jail with a $250,000 fine.

A CISO looking back, “Dear younger me…”

Dear Younger me

By Gary Hayslip, Vice President, Chief Information Security Officer, Webroot

Recently one beautiful night here in San Diego at a concert with my wife of thirty years, I listened to MercyMe play a song, “Dear Younger Me.” As I listened to the music, I found myself reflecting on decisions I had made over the last twenty years in my career in both information technology and cybersecurity. I remembered decisions that I made that had a profound impact on my family or employees and decisions I passed on because I lacked experience or the confidence to see my path forward. I found in retrospection this review to be quite sobering and I thought to myself what advice would I have given to my “younger me.” Would that advice have made a difference? Would I have listened and been better off for taking a different path than the one I am now on? For several hours after that concert, I could not get let this go, so instead, I created a list and finally at 3:00 am the next morning I fell asleep.

I realize now that much of my mentoring, writing and public speaking has been a way for me to speak to the “younger me’s” that are coming into our community. I hope the following advice provides some value and helps as you walk your path. I enjoyed creating this list, and the memories it contains today are as sharp as twenty years ago.

1.      It’s ok to take risks – when I was younger I was risk-averse, it was everything by the book, and I stayed in my box. That is fine as an analyst when you are entry level; however, when you move up in experience and leadership taking risks are expected. At times as a leader, you will have to make independent decisions, and you won’t have all of the information so you will have to make a decision. It’s ok, making that decision won’t end your career it will help you grow.

2.      An organizations culture can be a friend – I remember many times I tried to fight “this is how we do things around here.” I can’t count the times as a CIO or CISO I bashed my head and department against business culture thinking I would be the person to make it change. Well, years of experience has shown me that business culture improves through trust and visibility. It takes time to build that up with employees, and you can effect change if you put the time in and be patient. Employees have to understand the value of why change is needed and once they do the momentum to do something new can be fantastic to behold.

3.      It’s not always a tech issue – As a network engineer and later a security architect, I felt many of the problems we had were because we didn’t have the right technology to correct an issue. Years later I now realize many problems facing a security team, information technology team or even a DevOps team can be traced to bad workflows and business processes. Yes, that’s right. I am admitting uninformed business decisions can drive many issues that organizations buy technology to mask. If you are dealing with liabilities, understand the underlying causes before you expend resources to mitigate it, this will save you a lot of late nights and money in the long run.

4.      Information Technology department is not the enemy – working in security I have had a love/hate relationship with the IT Department. However, whether you like it or not as a CISO you can’t do your security projects and initiatives without the help of the CIO and her band of merry technicians so learn to collaborate and support each other. Besides, you want to know what projects they are doing so you can manage the risk. To get that trust you need to give some in return and its ok.

5.      Cybersecurity is enterprise risk – in security, you are not some digital ninjas, ok sometimes you are. But really, security is about managing risk through the use of processes, frameworks, people, and technology. I am embarrassed that when I was younger, I thought being in cybersecurity was super squirrel special but when you get down to it you are providing services to your organization just like the IT department except yours are different. That doesn’t mean we can’t take pride in working in our career field. I just believe we can serve with humility and be more productive.

6.      Working for the government is pretty cool – this is one decision I am happy I made, and I would recommend it for people starting in our career field. The level of experience, authority, projects, teams, and responsibility I received working in federal civil service for six years were pretty unique. The freedom I was given to make decisions, manage initiatives, fail at times, and grow as a leader and mentor is standard for government leaders, and I find it has made me more well-rounded as a security and business executive.

7.      Continuing education is part of the job –  I have spoken about this numerous times and have learned over the years, if you work in the cybersecurity field you will always be educating yourself on something so get used to it. I fought it for a while, figured I had my CISSP and I was done. Then I noticed the pace of change going on in the business, and I came to the realization I was just getting started. So embrace learning, and it will pay dividends in the long run for you and be sure to share this knowledge with your teams for their benefit as well.

8.      Red flags a warning – I have written articles on this, but I will repeat it one more time, beware of red flags in an interview. I know we all have the sense that we will do great in our new job if we can get that interview to make our case. That may be so, but we should also not be afraid to walk away. If you see the red flags, I mention in the linked article have some common sense to realize you are not getting hired to come in and fix their issues. Save yourself the heartache and sleepless nights and find a role that is a better fit for you and your family.

9.      Business knowledge is essential – this may not be required starting as an analyst or a security engineer. However, the longer you are in our career field and move into leadership roles the decisions you make are not always related to technology or security. Many are decisions related to resources, project management, and strategic planning. If you want to be a CISO get comfortable with making business decisions. If you need education and mentoring to mature those required skillsets, don’t be afraid to get them. Completing my executive MBA at San Diego State University was one of the best decisions I ever made.

10.  Manage your stress – start early and manage it often. In cybersecurity, much research has been done about the sustained effects of stress on security leaders and their teams. Being military I figured it wasn’t anything different than what I was used to when I was in uniform, so I just accepted the sustained stress as part of the job. I am here to say that is stupid and was a very bad decision on my part. If you don’t manage the stress cybersecurity brings to you as a CISO, it will control you, and you will not like it. Rick McElroy and I spoke about this at RSA this year, and it’s a fact that this issue is having an impact on our community and both of us have lost close friends and peers. Faith, family, friends, plus mentoring and community involvement. Tie that with some physical workouts, and you are on the mend. Take care of yourself; we need everyone in our community.

I am going to keep this list short, in actuality, I was up writing and created a list of over thirty things to talk about, but as my friend and peer, Sam Curry once told me – keep it short, you can always write another article <smile>. In closing, I hope some of these early morning musings help you and strongly encourage you to start early don’t come to the end of your career in cybersecurity with regret – leave a legacy.

This article was originally posted here and is published here with permission.

Accenture opens Federal Cyber Center in San Antonio

Accenture Federal Services San Antonio Cyber Center

Accenture has launched the Accenture Federal Services (AFS) Cyber Center, a state-of-the-art facility in San Antonio that provides cybersecurity capabilities on an as-a-service basis to help government agencies and the Department of Defense manage, detect and respond to the increasing volume and velocity of cyber threats that target government networks.

The Cyber Center offers a suite of security-as-a-service solutions and leading-edge capabilities in advanced adversary simulation, orchestration & automation, and managed detection and response.  An interdisciplinary team of advanced cyber defense experts deploys advanced technologies — including artificial-intelligence-based cyber intelligence — to help government agencies quickly and cost-effectively identify, emulate and eliminate threats.

“Government agencies need cybersecurity solutions that can keep pace with the increasing complexity, volume and speed of today’s threat landscape,” said John Goodman, chief executive of Accenture Federal Services. “Our advanced cyber capabilities and experienced cybersecurity specialists are delivering the threat intelligence and elimination services that our clients need to ensure mission success and resilience today and in the future.”

The Cyber Center is part of a larger AFS expansion in San Antonio. The company currently employs more than 1,300 people at its two primary San Antonio locations and recently announced plans to invest $5 million and add 500 full-time jobs over the next four years to enhance and expand the operations of its Advanced Technology Center in the city.

“We’re proud to partner with Accenture Federal Services in building the next generation of tech talent to serve and protect the nation, right here in the heart of San Antonio,” said Ron Nirenberg, Mayor of the City of San Antonio. “The new Accenture Federal Services Cyber Center, at the leading edge of innovation, will help us to grow and build our cyber workforce, and further strengthen our standing as a premiere technology and cybersecurity hub in the U.S.”

Accenture is also extending its commitment to provide student internships and apprenticeships that advance industry-relevant skills and provide on-the-job training opportunities to help train the next generation of U.S. technology talent. AFS recently became the anchor industry partner for San Antonio Cyber P-TECH, which gives students the skills, credentials and industry-specific associate degrees necessary for high-wage, high-demand careers in cybersecurity.

“San Antonio is rapidly becoming one of the most important technology hubs in the United States,” said Ben Peavy, Accenture’s office managing director in San Antonio. “By investing in internships, apprenticeships and other professional-development opportunities for local students and workers, and by creating well-paying jobs in the community, Accenture Federal Services is helping build a next-generation federal technology workforce here in the heart of San Antonio.”

Obsidian Security appoints data ethicist Laura Norén as Vice President of Privacy & Trust

Partnership

BUSINESS WIRE: Obsidian Security, a cybersecurity company providing intelligent identity protection for hybrid enterprises, announced the appointment of Laura Norén as Vice President of Privacy and Trust. Previously serving as the Director of Research, Norén brings a decade of experience in the sociotechnical impact of technological advances, including five years working on the ethical implications of applied data science.

Obsidian is building its technical stack and organizational structure to become a privacy and data ethics leader within the cybersecurity industry. Establishing an executive-level role to protect data subjects’ privacy and advocate for fairness in statistical and machine learning models is part of a larger effort to unite privacy principles and data ethics with technical advances in identity-centric cybersecurity. As Obsidian’s identity intelligence platform gains market traction, the regulatory environment becomes more complex, and demands for responsible data practices have captured the public attention, technically rigorous privacy and identity governance is crucially important.

Norén’s new role at Obsidian is a proactive privacy and data ethics position integrated into the data science and engineering teams, a first in the cybersecurity industry. In a systematic sample of cybersecurity companies exhibiting at RSA 2019, the US’s largest cybersecurity conference by attendance, only 12% had roles dedicated to privacy or ethics and most of those focused on compliance with limited influence on early-stage product development and model fairness.

“At Obsidian, we believe data ethics is more than a compliance issue. Because we are identity-centric and driven by machine learning we have to take responsibility for impacts on customers and employees. Laura’s statistical background and capacity to understand the human impact of applied data science are a competitive advantage for us. She’s here to look out for the interests of the employees and customers we protect,” said Glenn Chisholm, CEO of Obsidian Security who added that Norén is also the company’s general data protection officer for EU facing customers.

Before joining Obsidian in 2018, Norén was a Moore-Sloan postdoctoral associate at NYU’s Center for Data Science where she wrote and taught the first Data Science Ethics course in the Department of Applied Statistics. She maintains an active scholarly agenda and holds visiting scholar appointments at NYU’s Courant Institute of Mathematical Sciences and UC-Berkeley’s Division of Data Science. Norén serves as an advisor to the Moore-Sloan Alumni Network and Project Lead the Way, a K-12 STEM curriculum developer serving 3 million students. She is a frequent speaker at data science conferences, corporate workshops, and an active writer, including for her Data Science Community Newsletter. Norén holds a PhD in sociology from NYU and undergraduate degrees from MIT.

Tech Mahindra and i2Chain collaborate to secure confidential and classified customer information

Tech Mahindra Ltd., a provider of digital transformation, consulting and business reengineering services and solutions, announced a strategic collaboration with i2Chain Inc., a San Francisco-based startup, leveraging next-gen technologies to secure customer information and data assets.

Through this partnership, Tech Mahindra and i2Chain will offer a blockchain-based cybersecurity application to customers that is easy to use and provides information owners with an unprecedented level of control as to how, when and where other users can access their information, with the potential to substantially reduce the frequency and costs of security incidents.  It enables enterprises and users to secure, share and transact with integrity and confidence, and is fully GDPR (General Data Protection Regulation) compliant.  The application also makes “chained” information and identity tamperproof, and records all actions taken against a file in an immutable blockchain, fully accessible to support audits and forensics.

Vivek Agarwal, Head of Corporate Development and Portfolio Companies, Tech Mahindra, said, “The size and volume of data enabled with the advent of 5G networks presents a challenge for enterprises to provide cost-effective data security at the speed of business. I am excited to see that i2Chain can be leveraged as a strategic tool to secure high speed and high-volume information transactions especially in highly regulated industries including Finance, Media & Telecom, and Healthcare.”

Tech Mahindra will also provide consulting and other professional services, for the planning, deployment and ongoing support of the application to the users.

Rajesh Dhuddu, Global Practice Leader – Blockchain, Tech Mahindra, said, “This collaboration will enable Tech Mahindra to offer its customers across industries, an innovative and intuitive application to secure enterprise information and data assets through its entire life cycle. As part of the TechMNxt charter, we are actively building a partner ecosystem and leveraging next-gen technologies to empower our customers to address their underserviced and unaddressed needs. Our strategic partnership with i2Chain is an important step in this direction.”

Ajay Jotwani, co-founder and CEO, i2Chain, said, “We are delighted to partner with Tech Mahindra, a Forbes Top 100 Digital Company, with a sterling reputation for service, innovation and technology leadership. We are very excited about the solution we can offer to our mutual clients to help them secure information end-to-end while taking a very positive step into blockchain-based solutions for their businesses.”

As part of the TechMNxt charter, Tech Mahindra is betting big on next-gen technologies like Blockchain, Cybersecurity, Artificial Intelligence, Machine Learning, 5G, Internet of Things (IoT), Robotics, and Analytics. Tech Mahindra is also collaborating and creating a disruptive and innovation-led ecosystem with some of the finest start-ups and academia, and drawing from the millennial workforce to create cutting-edge technology solutions and services for its customers.

Disgruntled employee charged with hacking 15 client websites

Patchwork BADNEWS, APT31 threat group

An Indian national based out of Dubai has been charged for hacking 15 client websites after 4,000 dirhams ($1,080) was deducted from his salary by his employer.

According to reports, the accused, a 33-year-old computer programmer with a media firm in Dubai resigned from his post and threatened to hack its client websites over the financial row. “He sent WhatsApp messages to another programmer at the company saying that he will hack the websites if the company did not repay him the 4,000 dirhams deducted from his salary,” said the owner of the company. “He was informed that the deduction would be made if he resigned before the end of the probation period.”

Upon investigation into the personal computer of the accused, cyber sleuths confirmed that he had accessed the websites of clients. The man has been sentenced to three months in prison followed by deportation to India.

Revenge hacking isn’t a new phenomenon. There have been multiple instances when employees got back at their companies after they felt they were wronged. Brian P. Johnson, a former IT specialist and systems administrator for Georgia-Pacific launched an attack against the factory he previously worked after his frustration with the company over his unexpected termination. In revenge, Johnson would connect to the company’s network and make changes to settings and configurations, and sometimes even brought production to a halt. He was later apprehended by the FBI. In another instance, a former employee from Marriott allegedly hacked into the reservation system to change the room tariffs. The standard tariff between $159 and $499 was slashed to $12 and $59 for nearly 3000 rooms. The revenge resulted in a loss of over $50,000 to the hotelier.

Wipro hacked in a state-sponsored attack, begins forensic investigation

Indian IT outsourcing and consulting giant Wipro notified the company was recently breached after a state-sponsored phishing attack was launched against it. The company stated that it was ‘dealing with a multi-month intrusion from an assumed state-sponsored attacker,’ in a recent statement.

“We detected a potentially abnormal activity in a few employee accounts on our network due to an advanced phishing campaign. Upon learning of the incident, we promptly began an investigation, identified the affected users and took remedial steps to contain and mitigate any potential impact,” Wipro Ltd said in a statement to Economic Times.

The attack surfaced at its headquarters in the Indian city of Bengaluru. Wipro traced malicious activity on the network and the company have begun a forensic investigation of the incident.  “We are leveraging our industry-leading cybersecurity practices and collaborating with our partner ecosystem to collect and monitor advanced threat intelligence for enhancing security posture. We have also retained a well-respected, independent forensic firm to assist us in the investigation. We continue to monitor our enterprise and infrastructure at a heightened level of alertness,” the statement added.

According to reports from Kerbs On Security, “One source familiar with the forensic investigation at a Wipro customer said it appears at least 11 other companies were attacked, as evidenced from file folders found on the intruders’ back-end infrastructure that were named after various Wipro clients.”

Wipro is now in the process of building out a new private email network because the intruders were thought to have compromised Wipro’s corporate email system for some time. The source also said Wipro is now telling concerned clients about specific ‘indicators of compromise’, telltale clues about tactics, tools and procedures used by the bad guys that might signify an attempted or successful intrusion.”

Infosec Superwoman: Barbara Endicott-Popovsky

Barbara Endicott-Popovsky is the founder and lead instructor for the Certificate in Information Security & Risk Management. She also teaches cybersecurity in several UW degree programs and is the executive director of the Center for Information Assurance and Cybersecurity, responsible for developing cybersecurity curriculum and programs. She won a Teaching Excellence Award from UW Professional & Continuing Education in 2008 and received the University Professional & Continuing Education Association’s Excellence in Teaching Award for their West Region in 2014. In an exclusive interview with Augustin Kurian of CISO MAG, Barbara talks about her journey, evolution of cybersecurity, and representation of women in the space.

Tell us about your journey so far. You are a veteran in the space. How did you become a trainer for cybersecurity at a time when information security space was relatively unknown?

Out of college, while working for a major manufacturing firm, I spotted a man-in-the-middle attack on a local area network. When I reported it to leadership, they told me that I had a great career ahead of me but that I should keep observations like this quiet or people would think I was overly suspicious. This was in 1985 and it was really the start of the era of distributed processing, when IT departments would redirect computing power from the perimeter defenses of mainframes and move it on the factory floor, causing unknown vulnerabilities in the process. That realization sparked my interest in cybersecurity and made me curious about the blind spots that other people had regarding the unintended consequences of policy choices we’d made.

Tell us about the changes and evolution you personally witnessed in the sector?

The average person doesn’t realize we are in a state of war online. That’s the context in which we carry out personal financial transactions online – shop, pay our mortgage, whatever. This has changed who needs to know about cybersecurity and what they need to know. It’s no longer just about keeping the bad guys out of our systems because, truth be told, they’re living there now. The probability of being hacked and losing data is so great that it’s simply a function of how valuable what you own is to the other party. I like to say, ‘the probability is 1.’

A career in cybersecurity can lead you down so many different specialized paths due to its reach: for example, you could specialize in compliance, legal, or privacy. What’s great about this is that it means it’s a field that’s now attracting people with a wide diversity of interests. The expansion of cybersecurity pathways also means you don’t have to be deeply technical, which seems to be the imagined barrier to entry that everyone has in mind. Myriad people in different careers could enter this field simply be reskilling, upskilling, etc., which is why we offer both degree programs, as well as professional certificate programs in cyber-related fields at the University of Washington.

Tell us your thoughts about the upcoming CCPA and how it is set to be the GDPR for the United States? Do you think it was high time the U.S. had its own GDPR of sorts?

In short, yes, I do. I appreciate the European GDPR. Culturally, the Europeans were far more skeptical and aware of individual privacy issues, and companies have had to follow suit. For example, Microsoft is a U.S. company, but it’s international and they can’t have corporate privacy regimes for each country. The Internet doesn’t work that way. You must build the systems to the most stringent standards, and GDPR raised the bar.

Having said that, I appreciate the coming of new privacy standards to the U.S. Please realize that regulations are lagging the advance of technology and, therefore, implementation of these new regimes will not match perfectly. Individuals can’t expect regulations to keep them safe. It will require that all of us take measures to safeguard our data and do business online advisedly. Every human online should perform good cybersecurity practices.

Tell us a bit about the role of certifications. What type of careers in government and industry do cyber certificates prepare one for?

Learning in cybersecurity is never-ending given how the field is evolving so quickly. The notion of earning a degree each time you change roles isn’t feasible. That’s why professional certificates are ideal – they’re a fast and affordable way to close a skill gap you may have – and if they’re dispensed by a credible provider, they are meaningful to a current or prospective employer. At the UW, programs such as our Information Security and Risk Management professional certificate provide students the foundation for jobs in the full range of cybersecurity pathways.

Women in cybersecurity have been a widely discussed topic. Yet, women only make up 11% of the global cybersecurity workforce which has been a stagnant figure since 2013. What do you think are the reasons for the trend?

In the United States, I’ve observed that women consider the field to be too technical, preferring to work with people rather than technology. I don’t see that same reluctance among my international female students. I have to think it must be something tied to the culture—a meme that ‘girls don’t like this work.’

Some say that women don’t like the culture of cybersecurity organizations—they are too rough, too male, unfriendly—perhaps intimating bias. I’ve only had to address a couple of instances of clear female bias in my career; it may have been more prevalent, but my nature is goal-driven and curious, so I don’t allow myself to be distracted from my goals. In my experience, if you are passionate about what you are doing, distracting nonsense fades into the background. Find your passion, know how to prepare yourself, and then the rest of this resolves in the background.

Several studies around women in cybersecurity point out how many a time, the disparity traces its root back to school. How can this be changed?

Lack of awareness among those advising students/girls of the many opportunities in high paying cybersecurity careers is at the root of the problem. Colleagues who have held cybersecurity events specifically for young women have found a huge interest can be developed. The field is fun, exciting, ever-changing—like being a sleuth, tracking down adversaries, putting a puzzle together.

This field wasn’t here 20 years ago when educators and advisors were getting prepared to teach and counsel. We need targeted programs to raise awareness among educators from K-12 through bachelor’s degree programs. We need a pipeline.

In the meantime, there is a move toward developing shorter-term programs, like our certificates, that jump start those in mid-career who want to transition to a lucrative, exciting field.

Diversity in the information security space. What are drawbacks of not having more participation from women? Do you also think more participation from women will efficiently close the massive skill-gap that has marred the cybersecurity space?

Let me start by explaining why I think having more women in cybersecurity makes us all safer. In cyber, you need diverse points of view or you’ll miss potential threats. You must be right 100 percent of the time. The flaw hypothesis methodology – with which I fully agree – ensures having a diversity of perspectives when you form a vulnerability assessment team. This diversity is critical because if your organization recruits people with similar backgrounds, you’ll end up seeing everything the same way; however, if you have a diversity of views, then your organization will benefit from a wider situational awareness of possible flaws in the system.

What I would really recommend women do is set their sails and don’t look back. As I mentioned, there are 33 different pathways in cyber according to the NIST National Initiative for Cybersecurity Education. There is something for everybody – pathways range from purely managerial to deeply technical. Go through the framework and find what you’re interested in. Think about your gaps and how to fill them with further education and training. I encourage women to do what they’re passionately interested in and be persistent in pursuing their goals.

Microsoft issues alert over Outlook hack

Technology giant Microsoft has issued an alert to several users of over its mail platform Outlook hack. In a wordy notification, it stated hackers may have accessed data sent by several users on the platform between January 1 and March 28.

“Upon awareness of this issue, Microsoft immediately disabled the compromised credentials, prohibiting their use for any further unauthorized access. Our data indicate that account-related information (but not the content of any e-mails) could have been viewed, but Microsoft has no indication why that information was viewed or how it may have been used. As a result, you may receive phishing emails or other spam mails. You should be careful when receiving any e-mails from any misleading domain name, any e-mail that requests personal information or payment or any unsolicited request from an untrusted source,” it said in a statement.

According to Microsoft, apart from the contents of the emails which includes attachments, hackers may have also accessed email addresses, folder names, subject lines from both senders and recipients.

It is still unclear what the hackers target and why they launched an attack like this. “We addressed this scheme, which affected a limited subset of consumer accounts, by disabling the compromised credentials and blocking the perpetrators’ access,” the report quoted a Microsoft spokesperson as saying.

The tech giant also pointed out that email login credentials were not directly impacted by the incident, however, it has cautioned the users to reset the passwords.