Russian hackers were able to steal US government emails after attacking Microsoft

russian flag
(Image credit: Shutterstock)

Russian hackers have taken advantage of a cyber attack on Microsoft to steal emails from the accounts of officials working in several US federal agencies.

The US Cybersecurity and Infrastructure Security Agency (CISA) revealed in a statement that the breach is a result of the threat actor tracked by Microsoft as ‘MidnightBlizzard’ and known more widely as APT29, which has strong links to the Russian Foreign Intelligence Service.

CISA said that the hackers gained access “through a successful compromise of Microsoft corporate email accounts.”

Perfect espionage opportunity

“Midnight Blizzard’s successful compromise of Microsoft corporate email accounts and the exfiltration of correspondence between agencies and Microsoft presents a grave and unacceptable risk to agencies,” CISA said in the statement, but did not disclose the agencies affected or the breadth of the damage.

An emergency directive was issued by the agency stating that email accounts belonging to civilian government agencies needed to be secured as a result of the attack on Microsoft, upon which many government agencies rely for email communications.

Microsoft first revealed that it was under attack in January 2024, stating that Russian hackers had managed to gain access to corporate email accounts in the cybersecurity and legal departments. The tech giant later confirmed that the breach was not confined, and that corporate accounts belonging to organizations outside of Microsoft were also affected.

Since then, Microsoft has been working to remove all access from the MidnightBlizzard group in what the company has described as an “ongoing attack,” stating that the threat actors “may be using the information it has obtained to accumulate a picture of areas to attack and enhance its ability to do so.”

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
Russia
Major Russian hacking group shifts focus to US and UK targets
A red padlock image against a digital map of the earth in blue.
Midnight Blizzard hacking group hijacks RDP proxies to launch malware attacks
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Russian criminal gang Star Blizzard found hitting WhatsApp accounts
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
China US flags cropped
CISA says ‘no indication’ other US government agencies affected in Treasury hack
Image of someone clicking a cloud icon.
Microsoft's new expanded logging capabilities could mean big changes for US government devices
Latest in Pro
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Racks of servers inside a data center.
Modernizing data centers: an efficient path forward
Dr. Peter Zhou, President of Huawei Data Storage Product Line
Why AI commonization is so important for business intelligent transformation and what Huawei’s data storage has to offer
Wix automation
The world's leading website builder aims to save businesses time with new tool
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before