Skip to main content

Microsoft confirms documents were stolen in recent hacking attacks

microsoft confirms documents stolen recent hacking attacks ces booth
Image used with permission by copyright holder

It hasn’t been a pleasant start to 2014 so far for Microsoft: the Redmond-based company has been under attack from the Syrian Electronic Army across its email, social media and website systems. Now Microsoft has confirmed in a blog post that documents “associated with law enforcement inquiries” have been stolen as well.

It would seem that Microsoft’s announcement is designed to preempt any leaking of these documents by the SEA or other organizations that have got their hands on them. The blog post states: “Out of regard for the privacy of our employees and customers — as well as the sensitivity of law enforcement inquiries — we will not comment on the validity of any stolen emails or documents.”

As yet it doesn’t appear that any customer or user information was involved in the smash-and-grab, but Microsoft isn’t ruling it out either: “If we find that customer information related to those requests has been compromised, we will take appropriate action.”

“In terms of the cyberattack, we continue to further strengthen our security,” continues the post, penned by Adrienne Hall of Microsoft’s Trustworthy Computing Group. “This includes ongoing employee education and guidance activities, additional reviews of technologies in place to manage social media properties, and process improvements based on the findings of our internal investigation.”

To date, Microsoft’s woes at the hands of the SEA have included unauthorized blog posts, Twitter account hijacks and phishing attempts targeted at company employees. Adrienne Hall and her colleagues will be hoping for an easier ride for the rest of the year.

Editors' Recommendations

David Nield
Dave is a freelance journalist from Manchester in the north-west of England. He's been writing about technology since the…
No, 1Password wasn’t hacked – here’s what really happened
A person using the 1Password password manager on a laptop while sat on a couch.

Password managers have been struggling with security breaches in recent months, with LastPass suffering a particularly bad hack as a notable example. So when 1Password users got an alert last week saying their Secret Keys and passwords had been changed without their knowledge, they were understandably panicked. Luckily, all was not what it seemed.

That’s because AgileBits, the company behind 1Password, has just explained exactly what went wrong during that event. And while it wasn’t as bad as everyone first thought, it still doesn’t paint AgileBits in a particularly good light.

Read more
This Bing flaw let hackers change search results and steal your files
The new Bing preview screen appears on a Surface Laptop Studio.

A security researcher was recently able to change the top results in Microsoft’s Bing search engine and access any user’s private files, potentially putting millions of users at risk -- and all it took was logging into an unsecured web page.

The exploit was discovered by researcher Hillai Ben-Sasson at their team at Wiz, a cloud security firm. According to Ben-Sasson, it would not only allow an attacker to change Bing search results but would also grant them access to millions of users’ private files and data.

Read more
Apple’s security trumps Microsoft and Twitter’s, say feds
Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Apple has long held a reputation for rock-solid security, and now the U.S. government seemingly agrees after praising the company for its security procedures. At the same time, the feds have suggested Microsoft and Twitter need to pull their socks up and make their products much more secure for their users, according to CNBC.

In a speech given at Carnegie Mellon University, Cybersecurity and Infrastructure Security Agency Director Jen Easterly pointed to Apple as a company that took security and accountability seriously, and suggested other companies should take note.

Read more