Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Microsoft to Warn Users of State-Sponsored Attacks

Microsoft on Wednesday announced plans to inform users when it believes that their accounts have been targeted or compromised by actors working on behalf of a nation state.

Microsoft on Wednesday announced plans to inform users when it believes that their accounts have been targeted or compromised by actors working on behalf of a nation state.

The Redmond-based technology giant has become the latest tech company to start informing users on suspected state-sponsored attacks, after Google, Facebook, and Yahoo! announced similar plans. Earlier this month, Twitter also informed some users of attacks believed to be state-sponsored, but hasn’t formally announced intentions to continue doing so.

Scott Charney, Corporate Vice President, Trustworthy Computing at Microsoft, explains in a blog post that the tech giant is already working on identifying and preventing unauthorized access to Microsoft accounts, including Outlook.com and OneDrive. The company is already notifying users when it believes their accounts might have been compromised by a third party, while also guiding them on how to keep their accounts secure.

The new measure, however, is meant specifically for those situations when the company has evidence that the attacker might be state-sponsored. According to Charney, such attacks are usually more sophisticated or more sustained when compared to attacks performed by cybercriminals and other parties.

He also explains that these notifications do not mean that Microsoft’s own systems have been compromised, nor that the accounts have been necessarily compromised. However, it does mean that the company has evidence that the accounts have been targeted and that users should take additional steps to ensure that their accounts are kept secure.

At the same time, users are advised to check their computers and other devices to ensure that they haven’t been compromised by means of viruses or other type of malware. Moreover, they should make sure that all of their software is up to date.

According to Charney, users can take various steps to ensure their Microsoft accounts and their online personal information is secure, such as two-step verification, which means that the service will automatically ask for an extra security code when an attacker tries to access the account by guessing the password.

Users are also advised to use a strong password that contains a mix of letters, numbers and symbols, and change it often, as well as to watch their accounts for any suspicious activity by accessing the “Recent Activity” page.  They should also be careful of suspicious emails and websites, which might contain malware, and should always keep their computer software, especially an anti-virus program, up to date and running.

Advertisement. Scroll to continue reading.
Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.