5 ms·
Very curious as to the details they aren't releasing. If you read between the lines they are saying that accounts were compromised, but not through token steal
by frombody 6y ago
Very curious as to the details they aren't releasing.
If you read between the lines they are saying that accounts were compromised, but not through token stealing, which means the attackers got the passwords to the accounts, and likely skirted MFA requirements because they were already inside, or there were none.
While there are many avenues to steal passwords once you have the foothold the attackers did, it would be interesting to know the details as to how these particular accounts were compromised.
- mc32 6y agoWith a large and sophisticated Corp like Microsoft, wouldn’t they have a Zero Trust kind of security model which means certs and MFA regardless of location, behavior, etc. Obviously a lot we can only speculate about.
- somethingwitty1 6y agoI've worked in big companies like Microsoft, so can only comment from that perspective. Due to their size, they often do not have MFA regardless of location. Many didn't even use MFA. Most have been moving there, but it was long, multi-year projects. So I wouldn't be surprised if Microsoft doesn't have MFA for everything.
- isbjorn16 6y agoMSFT employee here: I don't know of an internal service that I use that doesn't have MFA. I am not going to make a broad statement saying they don't exist, I'm just saying I haven't found one yet. It's really annoying because I rarely have my phone on me when I'm at home so I have to go track it down. I'd be so happy if they let me use a yubikey :(
- srtjstjsj 6y agoMFA was standard in industry leaders 10 years ago.
- SV_BubbleTime 6y agoI read it as the possibility that MS source was somewhere it didn’t belong, but who knows?
- bluedino 6y agoA company like Microsoft probably gets “hacked” what, a hundred times a day? A thousand?
- frombody 6y agoCan you elaborate on your point? What I am saying is that these credentials can be stolen from MITM attacks, log files stored on random servers, or even basic mistakes like literally writing the password where other people can see it. Knowing what kind of operational mistakes Microsoft made that led to account compromises would help others from becoming victim to similar attacks.