Follow Us:
Monday, January 18, 2021

Microsoft says its systems were exposed to SolarWinds hack

Investigations so far show the malicious software wasn’t used to attack others and didn’t impact customer data or outward-facing systems.

By: Bloomberg | New Delhi | Updated: December 18, 2020 1:02:49 pm
microsoft, microsoft hack, microsoft system hack, microsoft update, cyber-attack, cloud, security software

Microsoft Corp. said its systems were exposed to the malware used in the Russia-linked hack that targeted US states and government agencies, adding that investigations so far show the malicious software wasn’t used to attack others and didn’t impact customer data or outward-facing systems.

The company is a customer of SolarWinds Corp., whose software the hackers are believed to have used to gain access to networks by installing malicious code. Microsoft found code related to that cyber-attack “in our environment, which we isolated and removed,” spokesman Frank Shaw said in a statement posted to his Twitter account. “We have not found evidence of access to production services or customer data. Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others.”

Reuters reported earlier that Microsoft was hacked and that its systems were used to attack other entities, citing people familiar with the matter.

Any successful cyber-attack on Microsoft, the world’s largest software maker and the second-biggest cloud-infrastructure provider, could damage its standing as a trusted provider of cloud software and security services. The software giant’s involvement emerged as the wider repercussions of the far-reaching hack became more clear. SolarWinds’ customers include government agencies and Fortune 500 companies, according to the company and cybersecurity experts. The departments of Homeland Security, Treasury, Commerce and State were breached, according to a person familiar with the matter. The US nuclear weapons agency and at least three states were also hacked.

Separately, Microsoft said in a blog post about the broader cyber-attack that it identified and has been working this week to notify more than 40 customers that the hackers targeted more precisely and compromised through additional and sophisticated measures. Amid its investigation of its own networks, Microsoft has also been helping customers monitor and cope with the attack.

Redmond, Washington-based Microsoft has become a significant vendor of cloud and security software and services, including to large government agencies, making its reputation for network protection critical to sales. The US Defense Department has awarded Microsoft a $10 billion cloud-computing contract, which is currently being contested in court by rival bidder Inc.

In an advisory Thursday that signalled the widening alarm over the recent breach, the US Cybersecurity and Infrastructure Security Agency said the hackers posed a “grave risk” to federal, state and local governments, as well as critical infrastructure and the private sector. The agency said the attackers demonstrated “sophistication and complex tradecraft.”

In a filing with the US Securities and Exchange Commission on Monday, SolarWinds said it believed its monitoring products could have been used to compromise the servers of as many as 18,000 of its customers.

📣 The Indian Express is now on Telegram. Click here to join our channel (@indianexpress) and stay updated with the latest headlines

For all the latest Technology News, download Indian Express App.