{"id":4603,"date":"2024-01-21T16:21:09","date_gmt":"2024-01-21T15:21:09","guid":{"rendered":"https:\/\/rock-the-prototype.com\/unkategorisiert\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/"},"modified":"2024-01-22T19:50:34","modified_gmt":"2024-01-22T18:50:34","slug":"cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors","status":"publish","type":"post","link":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/","title":{"rendered":"Cyberattack on Microsoft &#8211; Fact-based analysis of the attack vectors"},"content":{"rendered":"<p><\/p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><p>The <strong>cyberattack on Microsoft <\/strong>is the latest example of an extremely <strong>sophisticated cyberattack<\/strong>. This sophisticated <strong>IT hack<\/strong> on a <strong>widely used standard software<\/strong> proves how vulnerable even leading technology companies with advanced security systems can be when phishing and social engineering strategies come to fruition. With regard to IT security, this new IT security incident highlights the need to continuously monitor potential attack vectors and cybersecurity and to <strong>constantly adapt<\/strong> your own <strong>IT security strategies<\/strong> in response to such creative cyberattacks.<\/p>\n<p>Cyberattacks such as the one on Microsoft infrastructures are exemplary and must be regarded as a generally valid call for <strong>proactive protection<\/strong> in favor of <strong>robust cybersecurity architectures<\/strong> due to the widespread use of software solutions. Such an IT hack is therefore not only a wake-up call for the IT security community, but also always an opportunity to learn from experience and develop <strong>preventative cyber security strategies<\/strong>.<\/p>\n<p>In the following, we will examine the events of this <strong>attack on Microsoft software<\/strong> in detail in order to gain a deeper understanding of the methods used and the resulting challenges for our IT security. Find out with us how the cyber attack on Microsoft took place, what impact comparable cyber attacks have on your sensitive IT infrastructure and what this means for our secure digital future.<\/p>\n\n<h2><\/h2>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Podcast Folge 12 - SolarWinds Hack: Der unsichtbare Cyberdiebstahl - Rock the Prototype Podcast\" href=\"#\"><iframe class=\"lazyload\" style=\"border-radius: 12px;\" src=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27100%27%20height%3D%27352%27%20viewBox%3D%270%200%20100%20352%27%3E%3Crect%20width%3D%27100%27%20height%3D%27352%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-orig-src=\"https:\/\/open.spotify.com\/embed\/episode\/0qoHMUV1ZFCj5z4odFvsum?utm_source=generator\" width=\"100%\" height=\"352\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-2\"><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Inhaltsverzeichnis<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #ffffff;color:#ffffff\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #ffffff;color:#ffffff\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Background_What_happened_during_the_cyberattack_on_Microsoft_A_reconstruction_of_the_events\" >Background: What happened during the cyberattack on Microsoft? A reconstruction of the events.<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Detailed_explanation_of_the_Microsoft_attack_and_its_significance_for_the_future_of_cyber_security\" >Detailed explanation of the Microsoft attack and its significance for the future of cyber security<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Initial_situation_and_discovery_of_the_attack_at_Microsoft\" >Initial situation and discovery of the attack at Microsoft<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#What_is_the_extent_of_the_damage_and_what_information_was_obtained\" >What is the extent of the damage and what information was obtained?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Why_should_everyone_%E2%80%93_not_just_IT_security_specialists_%E2%80%93_be_interested_in_this_IT_security_incident\" >Why should everyone &#8211; not just IT security specialists &#8211; be interested in this IT security incident?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#What_attack_method_do_the_hackers_use\" >What attack method do the hackers use?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#How_could_this_happen\" >How could this happen?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#One_click_too_many_How_a_cyberattack_via_Microsoft_Teams_can_affect_any_of_us\" >One click too many: How a cyberattack via Microsoft Teams can affect any of us<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#When_did_this_strategic_cyberattack_on_Microsoft_begin\" >When did this strategic cyberattack on Microsoft begin?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Eliminate_unused_test_accounts_and_test_accounts_in_your_IT_infrastructure\" >Eliminate unused test accounts and test accounts in your IT infrastructure!<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Analysis_of_the_security_gaps\" >Analysis of the security gaps<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Classification_of_the_cyberattack\" >Classification of the cyberattack<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#What_was_the_motivation_behind_the_cyberattack\" >What was the motivation behind the cyberattack?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#What_motives_are_typically_used_to_carry_out_comparable_attacks_on_companies\" >What motives are typically used to carry out comparable attacks on companies?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Background_of_the_attackers_%E2%80%93_Who_is_Midnight_Blizzard_and_the_cybercriminals_around_the_organization\" >Background of the attackers &#8211; Who is Midnight Blizzard and the cybercriminals around the organization?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Cyber_group_known_for_sophisticated_cyberattacks_and_espionage_activities\" >Cyber group known for sophisticated cyberattacks and espionage activities<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#From_what_background_and_with_what_motivation_are_these_cyber_criminals_active\" >From what background and with what motivation are these cyber criminals active?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#Midnight_Blizzard_masters_of_covert_cyber_espionage_and_creative_cyber_attacks\" >Midnight Blizzard: masters of covert cyber espionage and creative cyber attacks<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#What_is_Microsofts_response_and_how_do_affected_organizations_react_to_the_hacker_attack\" >What is Microsoft&#8217;s response and how do affected organizations react to the hacker attack?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#What_can_we_learn_from_this_IT_security_incident\" >What can we learn from this IT security incident?<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"p1\"><span class=\"ez-toc-section\" id=\"Background_What_happened_during_the_cyberattack_on_Microsoft_A_reconstruction_of_the_events\"><\/span>Background: What happened during the cyberattack on Microsoft? A reconstruction of the events.<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The cyberattack that Microsoft recently experienced was both precise and complex. The IT security incident was discovered on January 12, a date that now occupies a prominent place in the chronicle of cybersecurity.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Detailed_explanation_of_the_Microsoft_attack_and_its_significance_for_the_future_of_cyber_security\"><\/span>Detailed explanation of the Microsoft attack and its significance for the future of cyber security<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This hack is characterized by a certain sophistication: Midnight Blizzard, an IT hacker group linked to the Russian secret service, managed to gain access to highly sensitive areas using cleverly manipulated Microsoft Teams messages.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Initial_situation_and_discovery_of_the_attack_at_Microsoft\"><\/span><strong>Initial situation and discovery of the attack at Microsoft<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Hackers from the Russian, state-sponsored hacker group &ldquo;Midnight Blizzard&rdquo; (also known as Nobelium, Cozy Bear, APT29) succeeded in accessing emails from Mircosoft employees in November last year. The piquant thing is that the affected email accounts are high-ranking Microsoft managers and employees who are also supposed to be responsible for cyber security.<\/p>\n<p>This compromise of sensitive communication channels reveals a serious security risk, not only for Microsoft itself, but also for a number of its global Microsoft customers.<\/p>\n<h2><\/h2>\n<\/div><div class=\"fusion-video fusion-youtube\" style=\"--awb-max-width:800px;--awb-max-height:450px;--awb-align-self:center;--awb-width:100%;\"><div class=\"video-shortcode\"><priv-fac-lite-youtube class=\"fusion-hidden lty-load\" data-privacy-type=\"youtube\" videoid=\"So-e6AjKwng\" params=\"wmode=transparent&amp;autoplay=1&amp;enablejsapi=1\" title=\"Rock the Prototype Podcast IT Security Special - Cybercrime-Story im Hoerspiel\" data-button-label=\"Play Video\" width=\"800\" height=\"450\" data-thumbnail-size=\"auto\" data-no-cookie=\"on\"><\/priv-fac-lite-youtube><div class=\"fusion-privacy-placeholder\" style=\"width:800px; height:450px;\" data-privacy-type=\"youtube\"><div class=\"fusion-privacy-placeholder-content\"><div class=\"fusion-privacy-label\">For privacy reasons YouTube needs your permission to be loaded. For more details, please see our <a class=\"privacy-policy-link\" href=\"https:\/\/rock-the-prototype.com\/datenschutzerklaerung\/\" rel=\"privacy-policy\">Datenschutzerkl&auml;rung<\/a>.<\/div><button data-privacy-type=\"youtube\" class=\"fusion-button button-default fusion-button-default-size button fusion-privacy-consent\">I Accept<\/button><\/div><\/div><\/div><\/div>\n<div class=\"fusion-text fusion-text-3\"><h3><span class=\"ez-toc-section\" id=\"What_is_the_extent_of_the_damage_and_what_information_was_obtained\"><\/span>What is the extent of the damage and what information was obtained?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The access to emails potentially gave the attackers insight into confidential data, such as company strategies, financial information and personal data, which illustrates the scope of the attack for both the business and private world and underlines the seriousness and potential reach of the current attack.<\/p>\n<h3>Why should everyone &ndash; not just IT security specialists &ndash; be interested in this IT security incident?<\/h3>\n<p>The incident throws a harsh light on the ever-growing threats that are brutally progressive in their dimensions and, above all, in terms of the frequency of events, and know no bounds. Cyber threats that even industry giants like Microsoft are facing.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_attack_method_do_the_hackers_use\"><\/span>What attack method do the hackers use?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In the cyberattack on Microsoft, the attackers used <strong>social engineering techniques<\/strong>, in particular <strong>phishing messages<\/strong> via <strong>Microsoft Teams<\/strong>, to obtain login credentials.<\/p>\n<p>These attack methods involve sophisticated <strong>social engineering techniques<\/strong>. In the cyberattacks on Microsoft, a special attack method was used via the MS Teams software. Microsoft Teams is a widely used communication tool that is used for chat, video conferencing, file sharing and digital team collaboration in many companies.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"How_could_this_happen\"><\/span>How could this happen?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The attackers used the integrity and confidentiality of the manipulated information as an attack vector and abused users&rsquo; trust in this platform to send targeted phishing messages that appeared to come from legitimate sources. These messages contained <strong>fake requests<\/strong> or <strong>links<\/strong> designed to trick recipients into revealing their login credentials, including their multi-factor <a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/authentication\/\" target=\"_blank\" title=\"Authentication is a multi-step process in identity management. Authentication in an IT system implements IT security functions that are realized by various security services and components.\" class=\"encyclopedia\">authentication<\/a> (MFA) codes. This fraudulent <strong>access to authentication information<\/strong> allowed the attackers to penetrate internal systems and email accounts.<\/p>\n<p>These messages were designed to appear trustworthy and were used to obtain login credentials from employees. This involved deceiving recipients to get them to reveal their multi-factor authentication codes.<\/p>\n<p>By successfully deceiving and exploiting trust in a known communication tool, the attackers were able to gain access to sensitive email accounts and other internal systems.<\/p>\n<p>Normally, MFA is a highly secure process that requires users to enter a code in addition to their password, which is usually generated on their mobile device. In this case, however, the attackers used phishing messages about Microsoft Teams to trick employees into revealing these MFA codes.<\/p>\n<p>Once the attackers had obtained the MFA codes, they were able to gain access to the employees&rsquo; email accounts. This access allowed them to access sensitive information and potentially carry out further fraudulent activities within the network.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"One_click_too_many_How_a_cyberattack_via_Microsoft_Teams_can_affect_any_of_us\"><\/span>One click too many: How a cyberattack via Microsoft Teams can affect any of us<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Cyberattacks such as the one on Microsoft Teams illustrate how easily even cautious users can become victims.<\/p>\n<p>Imagine you receive a message about Teams &ndash; a tool that you use every day for your work. The message appears to come from a colleague or IT support and asks for a quick confirmation or to click on a link. Without much thought and in the hustle and bustle of everyday working life, you could comply with this request.<\/p>\n<p>This is exactly where the attackers come in: They use well-known platforms and deceptively real messages to gain trust and elicit sensitive information such as MFA codes. This scenario shows how subtle yet effective cyber attacks can be.<\/p>\n<p>In the attack on Microsoft, the hackers exploited both technical and human vulnerabilities. Human vulnerabilities include, in particular, trust in familiar communication tools and standard software such as Microsoft Teams. The attackers used deception to trick employees into disclosing sensitive information. The aim of the attack was to gather confidential information that could be of strategic importance to both Microsoft and its customers. This included internal communications and potentially sensitive data on business strategies and security protocols.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"When_did_this_strategic_cyberattack_on_Microsoft_begin\"><\/span>When did this strategic cyberattack on Microsoft begin?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The cyberattack on Microsoft began at the end of November 2023 and was initiated by a so-called <strong>password spraying attack<\/strong>.<\/p>\n<p><strong>Password spraying attacks<\/strong> are a cyberattack technique in which the attacker combines a list of usernames with some commonly used or simple passwords. Instead of trying out many passwords on a single account, password spraying tests each password on a large number of accounts. This is usually done at a low frequency so as not to attract attention due to too many failed login attempts. A password spraying attack therefore uses common passwords across multiple accounts to bypass locking mechanisms.<\/p>\n<p>This attack method aims to bypass the usual account lockout mechanisms that are activated when too many incorrect login attempts are made from a single account.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Eliminate_unused_test_accounts_and_test_accounts_in_your_IT_infrastructure\"><\/span>Eliminate unused test accounts and test accounts in your IT infrastructure!<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The attackers cleverly targeted an older test tenant account that was no longer in productive use. This strategically clever approach enabled the hackers to penetrate the internal systems.<\/p>\n<p>A test tenant account is essentially a test account in the IT context, specifically in relation to <a href=\"https:\/\/rock-the-prototype.com\/en\/cloud-computing-cloud-technology\/cloud\/\" target=\"_blank\" title=\"What is cloud? Cloud or cloud computing moves data and programs from desktop PCs or servers in a company to remote cloud servers. Cloud storage therefore consists of a standard server network in a cloud data center or distributed across several cloud server locations.\" class=\"encyclopedia\">cloud<\/a> services such as Microsoft Azure or Microsoft 365. It is therefore a separate account or area that is set up specifically for testing purposes. These accounts are designed to provide developers or administrators with an environment in which they can test new applications, settings or updates without affecting the main production environment. As these test accounts are often not subject to the same stringent security protocols as production systems, they can be more vulnerable to security breaches.<\/p>\n<p>The attackers therefore deliberately targeted their hacks at an older, no longer actively used test tenant account, which may not have met the latest security standards. This choice offered them a less secure point of entry into Microsoft&rsquo;s internal systems. In the public announcement, Microsoft emphasized that only a &lsquo;very small percentage&rsquo; of employee email accounts, including executives and key employees, were affected. The incident reveals how subtle tactics can penetrate even supposedly secure networks and emphasizes the need for constant vigilance and updating of all system components.<\/p>\n<p>Microsoft&rsquo;s public statements state that only a &ldquo;very small percentage&rdquo; of Microsoft employee email accounts, including executives and employees in key areas such as cybersecurity and legal, were compromised in this way. During this attack, some emails and attached documents were exfiltrated. This incident shows the subtle methods that hackers can use to penetrate even seemingly secure networks.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Analysis_of_the_security_gaps\"><\/span>Analysis of the security gaps<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<div class=\"flex-1 overflow-hidden\">\n<div class=\"react-scroll-to-bottom--css-oqykh-79elbk h-full\">\n<div class=\"react-scroll-to-bottom--css-oqykh-1n7m0yu\">\n<div class=\"flex flex-col pb-9 text-sm\">\n<div class=\"w-full text-token-text-primary\" data-testid=\"conversation-turn-63\">\n<div class=\"px-4 py-2 justify-center text-base md:gap-6 m-auto\">\n<div class=\"flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion\">\n<div class=\"relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn\">\n<div class=\"flex-col gap-1 md:gap-3\">\n<div class=\"flex flex-grow flex-col max-w-full\">\n<div class=\"min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto\" data-message-author-role=\"assistant\" data-message-id=\"08f67928-a309-45fe-b174-f895714449c4\">\n<div class=\"markdown prose w-full break-words dark:prose-invert dark\">\n<p>When analyzing the vulnerabilities that were exploited in the cyberattack on Microsoft, it is important to recognize that smaller companies are often attractive targets for hackers.<\/p>\n<p>Such companies typically do not have the same extensive security measures as larger organizations. This implies a number of vulnerabilities, such as less stringent password security policies, limited IT resources for monitoring suspicious activity and often less awareness of the latest cyber threats.<\/p>\n<p>These factors make it much easier for hackers to easily gain access to inadequately protected systems and use them as a springboard for more far-reaching attacks.<\/p>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"Classification_of_the_cyberattack\"><\/span>Classification of the cyberattack<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To classify the cyberattack on Microsoft, we look at the type of attack, the vulnerabilities exploited and the severity levels:<\/p>\n<ol>\n<li><strong>Type of attack:<\/strong>\n<ul>\n<li>Social engineering and password spraying.<\/li>\n<li>Targeted attack on specific email accounts.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Exploited vulnerability:<\/strong>\n<ul>\n<li>Human factors (social engineering).<\/li>\n<li>Technical vulnerabilities in the IT security infrastructure (especially in older, non-productive test tenant accounts).<\/li>\n<\/ul>\n<\/li>\n<li><strong>Severity:<\/strong>\n<ul>\n<li><strong>Human factors:<\/strong> High. Social engineering attacks are effective because they are aimed at manipulating people and are difficult to prevent.<\/li>\n<li><strong>Technical weaknesses:<\/strong> Medium. The use of older, less secure accounts shows a security vulnerability, but the limited access indicates that critical systems have not been compromised.<\/li>\n<li><strong>Total:<\/strong> High. Due to the targeted nature of the attack, the high-ranking employees affected and the potential exfiltration of sensitive data, the overall severity is classified as high.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>A classification of this kind underlines the importance of a comprehensive security strategy that includes both technical measures and employee awareness.<\/p>\n<\/div>\n<\/div>\n<div class=\"mt-1 flex justify-start gap-3 empty:hidden\">\n<div class=\"text-gray-400 flex self-end lg:self-center justify-center lg:justify-start mt-0 -ml-1 visible\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"w-full pt-2 md:pt-0 dark:border-white\/20 md:border-transparent md:dark:border-transparent md:w-[calc(100%-.5rem)]\">\n<form class=\"stretch mx-2 flex flex-row gap-3 last:mb-2 md:mx-4 md:last:mb-6 lg:mx-auto lg:max-w-2xl xl:max-w-3xl\">\n<div class=\"relative flex h-full flex-1 items-stretch md:flex-col\">\n<div class=\"flex w-full items-center\"><\/div>\n<\/div>\n<\/form>\n<\/div>\n<h2><\/h2>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.IT-Security in Software Development - Rock the Prototype Podcast - Softwareentwicklung &amp; Prototyping\" href=\"#\"><iframe class=\"lazyload\" style=\"border-radius: 12px;\" src=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27100%27%20height%3D%27352%27%20viewBox%3D%270%200%20100%20352%27%3E%3Crect%20width%3D%27100%27%20height%3D%27352%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-orig-src=\"https:\/\/open.spotify.com\/embed\/episode\/3Uis0uViBdKlYxYS2nm1XU?utm_source=generator\" width=\"100%\" height=\"352\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-4\"><h2><span class=\"ez-toc-section\" id=\"What_was_the_motivation_behind_the_cyberattack\"><\/span>What was the motivation behind the cyberattack?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The motivation behind the cyberattack on Microsoft and similar attacks can be multifaceted. Cyber attacks regularly pursue targets such as:<\/p>\n<ol>\n<li><strong>Espionage:<\/strong> The collection of confidential information that could be valuable to governments or competing companies.<\/li>\n<li><strong>Financial gain:<\/strong> Through the sale of stolen data or ransom demands in the event of <a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/ransomware\/\" target=\"_blank\" title=\"Ransomware is therefore blackmail software, also known as an encryption Trojan. Ransomware is one of the most dangerous cyber attacks and is currently widespread. Ransomware is therefore blackmail software, also known as an encryption Trojan, which encrypts data or blocks access rights to directories, files and applications on attacked servers and computers. A ransom, typically in a cryptocurrency, is demanded for decryption. What is the most effective way to protect ourselves against ransomware attacks? Find out more now...\" class=\"encyclopedia\">ransomware<\/a> attacks.<\/li>\n<li><strong>Sabotage:<\/strong> The aim of disrupting or damaging operational processes, often for political or ideological reasons.<\/li>\n<li><strong>Reputational damage:<\/strong> The aim of damaging the reputation of a company or organization.<\/li>\n<\/ol>\n<p>In the case of Microsoft, the motives could be espionage and information gathering, especially if state-supported actors are involved. Such attacks are often strategically planned in order to achieve long-term goals.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_motives_are_typically_used_to_carry_out_comparable_attacks_on_companies\"><\/span>What motives are typically used to carry out comparable attacks on companies?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Cyber attacks on companies are just as complex and also pursue a wide variety of objectives. This often involves the theft or sale of commercially relevant data in order to gain financial advantages. The collection of confidential company information that could be of interest to competitors or governments also often plays a role. Some attacks are aimed at disrupting a company&rsquo;s operations in order to achieve either economic or political goals. Another motive may be the desire to damage a company&rsquo;s reputation. In some cases, the attacks are also ideologically motivated, with the attackers trying to spread their views or messages.<\/p>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Folge 11 - Die Dunkle Seite der Daten - Jenseits des Binaeren - Cybercrime Podcast\" href=\"#\"><iframe class=\"lazyload\" style=\"border-radius: 12px;\" src=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27100%27%20height%3D%27352%27%20viewBox%3D%270%200%20100%20352%27%3E%3Crect%20width%3D%27100%27%20height%3D%27352%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-orig-src=\"https:\/\/open.spotify.com\/embed\/episode\/2OxXGIOHYevPcdE1Gaeooc?utm_source=generator\" width=\"100%\" height=\"352\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-5\"><h2>Background of the attackers &ndash; Who is Midnight Blizzard and the cybercriminals around the organization?<\/h2>\n<p>Midnight Blizzard, also known as Nobelium, Cozy Bear or APT29, is a notorious cybercriminal group linked to the Russian <a href=\"https:\/\/de.wikipedia.org\/wiki\/Sluschba_wneschnei_raswedki\" target=\"_blank\" rel=\"noopener\">foreign intelligence service SVR<\/a>.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Cyber_group_known_for_sophisticated_cyberattacks_and_espionage_activities\"><\/span>Cyber group known for sophisticated cyberattacks and espionage activities<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>It is known for its sophisticated cyberattacks and espionage activities, mainly targeting governments, diplomatic institutions and IT service providers in the US and Europe. Its focus is on long-term and dedicated espionage of foreign interests. The group uses a variety of methods for initial access, including stolen credentials, supply chain attacks, exploitation of on-site environments and trusted relationships with service providers.<\/p>\n<div id=\"attachment_4598\" style=\"width: 1930px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-4598\" class=\"size-full wp-image-4597\" src=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware.jpg\" alt=\"Cyberattacks by professional hackers on standard software are a popular attack variant - hackers usually operate in highly specialized groups and act very precisely and extremely subtly. The mask is only part of the repertoire in symbolic photos like this one, but cyber criminals use AI-based code analysis to efficiently detect vulnerabilities and infiltrate companies undetected for as long as possible.  \" width=\"1920\" height=\"1280\" srcset=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-200x133.jpg 200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-300x200.jpg 300w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-400x267.jpg 400w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-600x400.jpg 600w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-768x512.jpg 768w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-800x533.jpg 800w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-1024x683.jpg 1024w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-1200x800.jpg 1200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware-1536x1024.jpg 1536w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberkriminelle-Hacker-Cyberattacken-auf-Standardsoftware.jpg 1920w\" sizes=\"(max-width: 1920px) 100vw, 1920px\"><p id=\"caption-attachment-4598\" class=\"wp-caption-text\">Cyber attacks by professional hackers on standard software are a popular attack variant &ndash; hackers usually operate in highly specialized groups and act very precisely and extremely subtly. The mask is only part of the repertoire in symbolic photos like this one, but cybercriminals use ki-based code analysis to efficiently detect vulnerabilities and infiltrate companies undetected for as long as possible.<\/p><\/div>\n<h3><span class=\"ez-toc-section\" id=\"From_what_background_and_with_what_motivation_are_these_cyber_criminals_active\"><\/span>From what background and with what motivation are these cyber criminals active?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The foreign intelligence service of the Russian Federation, SVR (Sluschba Vneschnei Raswedki), has a long and complex history dating back to the time of the Soviet Union. Originally founded as a civilian foreign intelligence agency in December 1920, the SVR has developed into a comprehensive espionage organization focusing on political, economic, scientific and technological areas. In addition to gathering information, the SVR also conducts counter-intelligence to monitor the activities of other intelligence services.<\/p>\n<p>With the restructuring of the Russian intelligence services, the SVR was given responsibility for telecommunications reconnaissance. The service is headquartered in the municipality of Sossenskoye, outside Moscow, and employs at least 15,000 people. SVR agents, often disguised as diplomats or journalists, are deployed worldwide. A special department, &ldquo;Main Department S&rdquo;, coordinates agents with false identities in various countries.<\/p>\n<p>The SVR&rsquo;s priorities have also shifted in response to geopolitical events. President Vladimir Putin has emphasized the importance of industrial espionage, especially after the sanctions against Russia since the invasion of Ukraine. The SVR plays a decisive role in the strategic planning and analysis of international processes for Russia.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Midnight_Blizzard_masters_of_covert_cyber_espionage_and_creative_cyber_attacks\"><\/span>Midnight Blizzard: masters of covert cyber espionage and creative cyber attacks<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Midnight Blizzard, also known as Nobelium, APT29, UNC2452 and Cozy Bear, is notorious for its consistent and persistent approach. The group always stays true to its goals and continuously adapts its methods to remain effective. Their attack tactics include a variety of techniques ranging from classic credential theft to complex supply chain attacks. A key aspect of their strategy is the use of on-premises systems as a starting point to later move into cloud environments.<\/p>\n<p>In addition, Midnight Blizzard manipulates the trust relationships between service providers and their customers in order to gain undetected access to the networks of downstream customers. The group is particularly well known for its use of specialized malware that attacks the Active Directory Federation Service (AD FS), including FOGGYWEB and MAGICWEB. This malware enables them to establish themselves deep in the victims&rsquo; networks and remain unnoticed in the long term. This variety of methods and their ability to constantly evolve make Midnight Blizzard a particularly dangerous and elusive cybersecurity adversary.<\/p>\n<\/div><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Podcast Folge 12 - SolarWinds Hack: Der unsichtbare Cyberdiebstahl - Rock the Prototype Podcast\" href=\"#\"><iframe style=\"width: 100%; max-width: 660px; overflow: hidden; border-radius: 10px;\" src=\"https:\/\/embed.podcasts.apple.com\/us\/podcast\/folge-12-solarwinds-hack-der-unsichtbare-cyberdiebstahl\/id1684107786?i=1000634096900\" height=\"175\" frameborder=\"0\" sandbox=\"allow-forms allow-popups allow-same-origin allow-scripts allow-storage-access-by-user-activation allow-top-navigation-by-user-activation\"><\/iframe><\/a>\n<div class=\"fusion-text fusion-text-6\"><h2>What is Microsoft&rsquo;s response and how do affected organizations react to the hacker attack?<\/h2>\n<p>Microsoft&rsquo;s <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/08\/02\/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams\/\" target=\"_blank\" rel=\"noopener\">response<\/a> to the cyberattack included various immediate measures as well as long-term strategies to improve cybersecurity.<\/p>\n<p>Microsoft responded with comprehensive measures immediately after the cyberattack was discovered. Initially, the software company focused on the immediate containment and investigation of the incident. The accounts and networks used by the attackers were quickly identified and blocked. In parallel, Microsoft informed the affected organizations and worked closely with them to assess the impact of the attack and take effective countermeasures.<\/p>\n<div id=\"attachment_4593\" style=\"width: 2570px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-4593\" class=\"size-full wp-image-4592\" src=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-scaled.jpg\" alt=\"Reaction in the Microsoft blog to Midnight Blizzard cyberattack\" width=\"2560\" height=\"1970\" srcset=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-200x154.jpg 200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-300x231.jpg 300w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-400x308.jpg 400w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-600x462.jpg 600w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-768x591.jpg 768w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-800x615.jpg 800w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-1024x788.jpg 1024w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-1200x923.jpg 1200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-1536x1182.jpg 1536w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Reaktion-im-Microsoft-Blog-auf-Midnight-Blizzard-Cyberattacke-scaled.jpg 2560w\" sizes=\"(max-width: 2560px) 100vw, 2560px\"><p id=\"caption-attachment-4593\" class=\"wp-caption-text\">Reaction in the Microsoft blog to Midnight Blizzard cyberattack<\/p><\/div>\n<p>In addition to acute crisis management, Microsoft placed a strong focus on improving its security infrastructure. This included the optimization of detection systems and the implementation of stricter access controls. By its own admission, the company has also intensified the training and sensitization of its employees in the area of cyber security in order to raise awareness of potential threats and establish a stronger security culture. Microsoft had <a href=\"https:\/\/news.microsoft.com\/de-de\/eine-neue-welt-der-sicherheit-microsofts-secure-future-initiative\/\" target=\"_blank\" rel=\"noopener\">already<\/a> announced a Secure Future Initiative (SFI) <a href=\"https:\/\/news.microsoft.com\/de-de\/eine-neue-welt-der-sicherheit-microsofts-secure-future-initiative\/\" target=\"_blank\" rel=\"noopener\">at the end of last year<\/a>.<\/p>\n<p>As part of the ongoing investigation, Microsoft is cooperating closely with law enforcement and security agencies to identify those behind the attack and develop preventative strategies against future attacks. In an effort to be transparent with its customers and the public, Microsoft publishes regular updates and detailed reports on the incident and the steps taken. This open communication demonstrates the company&rsquo;s commitment to protecting its systems and maintaining the trust of its users.<\/p>\n<\/div><div class=\"fusion-text fusion-text-7\"><h2><span class=\"ez-toc-section\" id=\"What_can_we_learn_from_this_IT_security_incident\"><\/span>What can we learn from this IT security incident?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To prevent attacks like the one on Microsoft, or at least effectively mitigate their impact, companies should apply the following security measures or mitigation strategies:<\/p>\n<ol>\n<li><strong>Strengthen password security:<\/strong> Use stronger password guidelines and change passwords regularly to make password spraying attacks more difficult.<\/li>\n<li><strong>Multi-level authentication:<\/strong> Implementation of multi-factor authentication (MFA) for all users to prevent unauthorized access.<\/li>\n<li><strong>Regular security audits:<\/strong> Review and update security systems to identify and address vulnerabilities.<\/li>\n<li><strong>Employee training:<\/strong> Regular cybersecurity training to raise awareness of phishing and other social engineering tactics.<\/li>\n<li><strong>Use of IT security software:<\/strong> Use of modern IT security solutions that can detect and block suspicious activities.<\/li>\n<li><strong>Network segmentation:<\/strong> Separation of critical systems and data to limit the spread of an attack.<\/li>\n<li><strong>Zero Trust principle: <\/strong>In contrast to conventional approaches that are based on trust-based networks, the Zero Trust <strong>principle <\/strong><a href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/zero-trust-beyond-vpn-why-the-virtual-private-network-is-in-the-shadow-of-zero-trust\/#Zero_Trust_und_seine_Prinzipien\" target=\"_blank\" rel=\"noopener\"><br>\n  <strong>Zero Trust<\/strong><br>\n<\/a> assumes that no user, device or network is automatically trustworthy.<\/li>\n<\/ol>\n<p>Experience has shown that these measures are very effective in significantly reducing the risk of cyberattacks and demonstrably increasing the security of company data.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><a class=\"fusion-modal-text-link\" data-toggle=\"modal\" data-target=\".fusion-modal.Rock the Prototype - Softwareentwicklung &amp; Prototyping Podcast iTunes\" href=\"#\"><iframe id=\"embedPlayer\" style=\"width: 100%; max-width: 990px; overflow: hidden; border-radius: 10px; transform: translateZ(0px); animation: 2s ease 0s 6 normal none running loading-indicator; background-color: #e4e4e4;\" src=\"https:\/\/embed.podcasts.apple.com\/de\/podcast\/rock-the-prototype-softwareentwicklung-prototyping\/id1684107786?itsct=podcast_box_player&amp;itscg=30200&amp;ls=1&amp;theme=dark\" height=\"450px\" frameborder=\"0\" sandbox=\"allow-forms allow-popups allow-same-origin allow-scripts allow-top-navigation-by-user-activation\"><\/iframe> <\/a><\/div><\/div><\/div><\/div>\n<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\"><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1144px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_3 1_3 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:5.76%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top-small:30px;--awb-margin-right-small:0px;--awb-margin-bottom-small:20px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.1;\">About the Author:<\/h2><\/div><div class=\"fusion-image-element\" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-1 hover-type-none\"><img decoding=\"async\" width=\"1920\" height=\"1920\" title=\"Sascha Block &ndash; Rock the Prototype\" src=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block.jpg\" alt class=\"img-responsive wp-image-3342\" srcset=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-200x200.jpg 200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-400x400.jpg 400w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-600x600.jpg 600w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-800x800.jpg 800w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block-1200x1200.jpg 1200w, https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2019\/09\/Sascha_Block.jpg 1920w\" sizes=\"(max-width: 1024px) 100vw, (max-width: 640px) 100vw, 400px\"><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_2_3 2_3 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:2.88%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-three\" style=\"--awb-margin-top-small:30px;--awb-margin-right-small:0px;--awb-margin-bottom-small:20px;--awb-margin-left-small:0px;\"><h3 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:26;line-height:1.2;\">Sascha Block<\/h3><\/div><div class=\"fusion-text fusion-text-8\"><p>I am <a href=\"https:\/\/www.linkedin.com\/in\/sascha-block-5785b9126\/\">Sascha Block<\/a> &ndash; IT architect in Hamburg and the initiator of Rock the Prototype. I want to make <a href=\"https:\/\/rock-the-prototype.com\/en\/prototyping-en\/prototyping\/\" target=\"_blank\" title=\"What is prototyping? Prototyping is both a process and a strategy for realizing ideas as quickly as possible.\" class=\"encyclopedia\">prototyping<\/a> learnable and experiential. With the motivation to prototype ideas and share knowledge around software prototyping, software architecture and <a href=\"https:\/\/rock-the-prototype.com\/en\/learn-programming\/programming\/\" target=\"_blank\" title=\"What is programming? When programming, a programmer creates a software program that can run on a machine. The code is created in one of the formally defined computer languages - which are countless, such as Java, PHP, C++ or C#, Perl and many many more.\" class=\"encyclopedia\">programming<\/a>, I created the format and the open source initiative Rock the Prototype.<\/p>\n<\/div><div><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-1 fusion-button-default-span fusion-button-default-type\" style=\"--button_accent_color:#ffffff;--button_accent_hover_color:#00ffff;--button_border_hover_color:#4ab4ff;--button_gradient_top_color:var(--awb-color3);--button_gradient_bottom_color:var(--awb-color3);--button_gradient_top_color_hover:var(--awb-color2);--button_gradient_bottom_color_hover:var(--awb-color2);\" target=\"_self\" href=\"https:\/\/rock-the-prototype.com\/programmieren-lernen\/javascript-die-perfekte-programmiersprache-um-programmieren-zu-lernen\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">JavaScript the perfect programming language to learn programming<\/span><\/a><\/div><div class=\"fusion-separator fusion-full-width-sep\" style=\"align-self: center;margin-left: auto;margin-right: auto;width:100%;\"><\/div><ul style=\"--awb-size:18px;--awb-line-height:30.6px;--awb-icon-width:30.6px;--awb-icon-height:30.6px;--awb-icon-margin:12.6px;--awb-content-margin:43.2px;\" class=\"fusion-checklist fusion-checklist-1 fusion-checklist-default type-icons\"><li class=\"fusion-li-item\" style=\"\"><span class=\"icon-wrapper circle-no\"><i class=\"fusion-li-icon fa-link fas\" aria-hidden=\"true\"><\/i><\/span><div class=\"fusion-li-item-content\">\n<p><a href=\"https:\/\/rock-the-prototype.com\/en\/\">rock-the-prototype.com<\/a><\/p>\n<\/div><\/li><\/ul><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cyberattack on Microsoft &#8211; Fact-based analysis of the attack vectors. The most recent example of a sophisticated cyberattack is the cyberattack on Microsoft. This new IT hack on widely used standard software proves how vulnerable even leading technology companies with advanced security systems can be. Cyberattacks such as the one on Microsoft infrastructures are exemplary and must be regarded as a generally valid call for proactive protection in favor of robust cybersecurity architectures due to the widespread use of software solutions.  <\/p>\n","protected":false},"author":1,"featured_media":4588,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[1234,1232],"tags":[2212,2225,2211,2204,2226,2220,2228,2203,2218,2227,2230,2205,2221,2219,1235,2208,2209,2217,1243,2210,2229,2207,2216,2213,2223,2222,2206,2215],"class_list":["post-4603","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-infrastructure","category-it-security","tag-apt29-en","tag-counterintelligence","tag-cozy-bear-en","tag-cyber-attack","tag-cyber-attack-prevention","tag-cyber-threat","tag-cyberattack","tag-cybersecurity-en","tag-data-exfiltration","tag-data-leak","tag-e-mail-compromise","tag-hacker-en","tag-industrial-espionage","tag-it-infrastructure","tag-it-security-en","tag-microsoft-en","tag-midnight-blizzard-en","tag-multi-factor-authentication-en","tag-network-security","tag-nobelium-en","tag-password-spraying","tag-phishing-en","tag-russian-secret-service","tag-security-gap","tag-security-measures","tag-security-response","tag-social-engineering-en","tag-svr-en-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber attack on Microsoft - analysis of the attack vectors<\/title>\n<meta name=\"description\" content=\"Detailed explanation of the cyberattack on Microsoft \u2705 What method of attack are the hackers using? \u2705 How could this happen? \u2705 Read now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber attack on Microsoft - analysis of the attack vectors\" \/>\n<meta property=\"og:description\" content=\"Detailed explanation of the cyberattack on Microsoft \u2705 What method of attack are the hackers using? \u2705 How could this happen? \u2705 Read now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/\" \/>\n<meta property=\"og:site_name\" content=\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-21T15:21:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-22T18:50:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberangriff-Microsoft.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sascha Block\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@rocktheprototyp\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sascha Block\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/\"},\"author\":{\"name\":\"Sascha Block\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#\\\/schema\\\/person\\\/fdb2f98edec62327712c2d26d981c081\"},\"headline\":\"Cyberattack on Microsoft &#8211; Fact-based analysis of the attack vectors\",\"datePublished\":\"2024-01-21T15:21:09+00:00\",\"dateModified\":\"2024-01-22T18:50:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/\"},\"wordCount\":5816,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/Cyberangriff-Microsoft.jpg\",\"keywords\":[\"APT29\",\"Counterintelligence\",\"Cozy Bear\",\"Cyber attack\",\"Cyber attack prevention\",\"Cyber threat\",\"Cyberattack\",\"Cybersecurity\",\"Data exfiltration\",\"Data leak\",\"E-mail compromise\",\"Hacker\",\"Industrial espionage\",\"IT infrastructure\",\"IT Security\",\"Microsoft\",\"Midnight Blizzard\",\"Multi-factor authentication\",\"Network Security\",\"Nobelium\",\"Password Spraying\",\"Phishing\",\"Russian secret service\",\"Security gap\",\"Security measures\",\"Security response\",\"Social engineering\",\"SVR\"],\"articleSection\":[\"IT infrastructure\",\"IT Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/\",\"name\":\"Cyber attack on Microsoft - analysis of the attack vectors\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/Cyberangriff-Microsoft.jpg\",\"datePublished\":\"2024-01-21T15:21:09+00:00\",\"dateModified\":\"2024-01-22T18:50:34+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#\\\/schema\\\/person\\\/fdb2f98edec62327712c2d26d981c081\"},\"description\":\"Detailed explanation of the cyberattack on Microsoft \u2705 What method of attack are the hackers using? \u2705 How could this happen? \u2705 Read now!\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#primaryimage\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/Cyberangriff-Microsoft.jpg\",\"contentUrl\":\"https:\\\/\\\/rock-the-prototype.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/Cyberangriff-Microsoft.jpg\",\"width\":1920,\"height\":1280,\"caption\":\"January 11, 2024, Brazil. In this photo illustration, the Microsoft logo is seen in the background of a silhouette of a person using a notebook\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/it-security\\\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/rock-the-prototype\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyberattack on Microsoft &#8211; Fact-based analysis of the attack vectors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/\",\"name\":\"Rock the Prototype - Softwareentwicklung &amp; Prototyping\",\"description\":\"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/#\\\/schema\\\/person\\\/fdb2f98edec62327712c2d26d981c081\",\"name\":\"Sascha Block\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g\",\"caption\":\"Sascha Block\"},\"description\":\"Ich bin Sascha Block \u2013 IT-Architekt in Hamburg und der Initiator von Rock the Prototype. Ich m\u00f6chte Prototyping erlernbar und erfahrbar machen. Mit der Motivation Ideen prototypisch zu verwirklichen und Wissen rund um Software-Prototyping, Softwarearchitektur und Softwareentwicklung zu teilen, habe ich das Format und die Open-Source Initiative Rock the Prototype geschaffen.\",\"sameAs\":[\"https:\\\/\\\/rock-the-prototype.com\",\"https:\\\/\\\/www.instagram.com\\\/rock_the_prototype\\\/\",\"https:\\\/\\\/x.com\\\/rocktheprototyp\",\"https:\\\/\\\/www.youtube.com\\\/@Rock-the-Prototype\\\/\"],\"url\":\"https:\\\/\\\/rock-the-prototype.com\\\/en\\\/author\\\/administrator-2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber attack on Microsoft - analysis of the attack vectors","description":"Detailed explanation of the cyberattack on Microsoft \u2705 What method of attack are the hackers using? \u2705 How could this happen? \u2705 Read now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/","og_locale":"en_US","og_type":"article","og_title":"Cyber attack on Microsoft - analysis of the attack vectors","og_description":"Detailed explanation of the cyberattack on Microsoft \u2705 What method of attack are the hackers using? \u2705 How could this happen? \u2705 Read now!","og_url":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/","og_site_name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","article_published_time":"2024-01-21T15:21:09+00:00","article_modified_time":"2024-01-22T18:50:34+00:00","og_image":[{"width":1920,"height":1280,"url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberangriff-Microsoft.jpg","type":"image\/jpeg"}],"author":"Sascha Block","twitter_card":"summary_large_image","twitter_creator":"@rocktheprototyp","twitter_misc":{"Written by":"Sascha Block","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#article","isPartOf":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/"},"author":{"name":"Sascha Block","@id":"https:\/\/rock-the-prototype.com\/en\/#\/schema\/person\/fdb2f98edec62327712c2d26d981c081"},"headline":"Cyberattack on Microsoft &#8211; Fact-based analysis of the attack vectors","datePublished":"2024-01-21T15:21:09+00:00","dateModified":"2024-01-22T18:50:34+00:00","mainEntityOfPage":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/"},"wordCount":5816,"commentCount":0,"image":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#primaryimage"},"thumbnailUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberangriff-Microsoft.jpg","keywords":["APT29","Counterintelligence","Cozy Bear","Cyber attack","Cyber attack prevention","Cyber threat","Cyberattack","Cybersecurity","Data exfiltration","Data leak","E-mail compromise","Hacker","Industrial espionage","IT infrastructure","IT Security","Microsoft","Midnight Blizzard","Multi-factor authentication","Network Security","Nobelium","Password Spraying","Phishing","Russian secret service","Security gap","Security measures","Security response","Social engineering","SVR"],"articleSection":["IT infrastructure","IT Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/","url":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/","name":"Cyber attack on Microsoft - analysis of the attack vectors","isPartOf":{"@id":"https:\/\/rock-the-prototype.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#primaryimage"},"image":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#primaryimage"},"thumbnailUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberangriff-Microsoft.jpg","datePublished":"2024-01-21T15:21:09+00:00","dateModified":"2024-01-22T18:50:34+00:00","author":{"@id":"https:\/\/rock-the-prototype.com\/en\/#\/schema\/person\/fdb2f98edec62327712c2d26d981c081"},"description":"Detailed explanation of the cyberattack on Microsoft \u2705 What method of attack are the hackers using? \u2705 How could this happen? \u2705 Read now!","breadcrumb":{"@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#primaryimage","url":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberangriff-Microsoft.jpg","contentUrl":"https:\/\/rock-the-prototype.com\/wp-content\/uploads\/2024\/01\/Cyberangriff-Microsoft.jpg","width":1920,"height":1280,"caption":"January 11, 2024, Brazil. In this photo illustration, the Microsoft logo is seen in the background of a silhouette of a person using a notebook"},{"@type":"BreadcrumbList","@id":"https:\/\/rock-the-prototype.com\/en\/it-security\/cyberattack-on-microsoft-fact-based-analysis-of-the-attack-vectors\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/rock-the-prototype.com\/en\/rock-the-prototype\/"},{"@type":"ListItem","position":2,"name":"Cyberattack on Microsoft &#8211; Fact-based analysis of the attack vectors"}]},{"@type":"WebSite","@id":"https:\/\/rock-the-prototype.com\/en\/#website","url":"https:\/\/rock-the-prototype.com\/en\/","name":"Rock the Prototype - Softwareentwicklung &amp; Prototyping","description":"Prototyping: Software Prototypen, Software entwickeln &amp; Programmieren im Team","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rock-the-prototype.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/rock-the-prototype.com\/en\/#\/schema\/person\/fdb2f98edec62327712c2d26d981c081","name":"Sascha Block","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/967c419542686b085600443beafb2e55ad1ef6532a0ad9b96d244cb24fd8c117?s=96&d=mm&r=g","caption":"Sascha Block"},"description":"Ich bin Sascha Block \u2013 IT-Architekt in Hamburg und der Initiator von Rock the Prototype. Ich m\u00f6chte Prototyping erlernbar und erfahrbar machen. Mit der Motivation Ideen prototypisch zu verwirklichen und Wissen rund um Software-Prototyping, Softwarearchitektur und Softwareentwicklung zu teilen, habe ich das Format und die Open-Source Initiative Rock the Prototype geschaffen.","sameAs":["https:\/\/rock-the-prototype.com","https:\/\/www.instagram.com\/rock_the_prototype\/","https:\/\/x.com\/rocktheprototyp","https:\/\/www.youtube.com\/@Rock-the-Prototype\/"],"url":"https:\/\/rock-the-prototype.com\/en\/author\/administrator-2\/"}]}},"_links":{"self":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts\/4603","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/comments?post=4603"}],"version-history":[{"count":26,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts\/4603\/revisions"}],"predecessor-version":[{"id":4631,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/posts\/4603\/revisions\/4631"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media\/4588"}],"wp:attachment":[{"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/media?parent=4603"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/categories?post=4603"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rock-the-prototype.com\/en\/wp-json\/wp\/v2\/tags?post=4603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}