Slashdot Mirror


Hackers Steal Law Enforcement Documents From Microsoft

wiredmikey writes "Microsoft on Friday said that attackers breached the email accounts of a "select number" of employees, and obtained access to documents associated with law enforcement inquiries. According to the company, a number of Microsoft employees were targeted with attacks aiming to compromise both email and social media accounts '..We have learned that there was unauthorized access to certain employee email accounts, and information contained in those accounts could be disclosed,' said Adrienne Hall, General Manager at Microsoft's Trustworthy Computing Group. 'It appears that documents associated with law enforcement inquiries were stolen,' Hall said. Targeted attacks like this are not uncommon, especially for an organization like Microsoft. What's interesting about this is that the incident was significant enough to disclose, indicating that a fair number of documents could have been exposed, or that the company fears some documents will make their way to the public if released by the attackers—which may be the case if this was a 'hacktivist' attack."

19 of 53 comments (clear)

  1. Ahh... by the_skywise · · Score: 5, Funny

    ""Microsoft on Friday said that attackers breached the email accounts of a "select number" of employees,"
    I see Microsoft uses hotmail internally too..

    1. Re:Ahh... by Anonymous Coward · · Score: 2, Interesting

      I see Microsoft uses hotmail internally too..

      Maybe, but what I'm really hoping for is their version of Snowdon to step forward and blow the whistle on a lot more of their nefarious activities.

      They're a deeply unethical, deceptive and dangerous company that's been doing a lot of damage for a long time. I'm sure there are people working for them that have consciences and would be considering stepping forward.

      If you're one of them, now would be a good time...

    2. Re:Ahh... by davester666 · · Score: 2

      But can you learn them?

      --
      Sleep your way to a whiter smile...date a dentist!
  2. Betting time! by fuzzyfuzzyfungus · · Score: 5, Insightful

    So, 'documents associated with law enforcement inquiries' seem like something of interest to two classes of people:

    (A): Anyone curious about how shocked, shocked, Microsoft actually is about massive electronic eavesdropping by the feds.

    (B): Technically sophisticated targets or likely targets of some law enforcement operation looking for information pertaining to their own case.

    Any guesses? One of those botnet groups that Microsoft periodically tries to disrupt checking to see if they need to start retaining a lawyer, or coming soon to wikileaks?

    1. Re:Betting time! by kbrannen · · Score: 4, Interesting

      How about (C), a new form of "Freedom of Information Act". :)

    2. Re:Betting time! by fuzzyfuzzyfungus · · Score: 3, Funny

      But it just isn't the same without the lawyers, and the obstructionism, and all those black highlighters. Kids these days, they'll never know the joy of being spitefully shipped boxes of badly photocopied documents tangentially related to your inquiry and seemingly intended to defeat it by sheer volume and unsearchability!

  3. Do we know that this is authentic? by Anonymous Coward · · Score: 4, Insightful

    Has anyone confirmed that the blog post disclosing this incident is actually authentic?

    One of the linked-to articles links to another article from the Seattle Times dated January 21, 2014 and entitled "Official Microsoft blog hacked again by Syrian Electronic Army".

    So at least one official Microsoft blog was apparently compromised within the past few days. If it happened once, there's the possibility that it could happen again.

    I would feel more comfortable trusting the information about this incident if it weren't coming from a Microsoft blog post, too. I think that confirming this information via some other official channel would allow more trust to be placed in its authenticity.

    1. Re:Do we know that this is authentic? by VortexCortex · · Score: 2

      Nice try NSA. You've already shown your hand. We know you can love kittens on any website in the world, it's obvious that you've snuggled this poor commenter's post to spread your delightful agenda.

  4. If microsoft==true then ??? by nyckidd · · Score: 3, Interesting

    If Microsoft can't educate their employees on how to avoid phishing / social engineering attacks what does this say for the rest of the world? Considering the fact that they have already had a number of other widely publicized incidents in the media recently, shouldn't they be on high alert?

    I really hope at some point they decide to release actual details on what really occured, because love or hate them, Microsoft could be the company that actually does something that might actually get through to end users.

  5. Monday's announcement: by pla · · Score: 5, Funny

    "So you know how we swore up and down for years that we didn't intentionally weaken Windows encryption for the NSA? Yeah, about that..."

    1. Re:Monday's announcement: by Tasha26 · · Score: 2

      Won't be long before NSA gets hit too. Afterall, they're the ones who opened pandora's box!

    2. Re:Monday's announcement: by DoofusOfDeath · · Score: 2

      The U.S. intelligence agencies torture people. That's a disincentive to hacking them.

  6. Annual report says MS unconcerned about security by raymorris · · Score: 4, Informative

    It does not appear that Microsoft is "on high alert".

    I recently read over the annual reports from major tech companies, looking at the business risks they report. This is an indication of how high level executives see the risks the company faces. Google, for example, has several paragraphs covering the damage to the brand, costly remediation, and potential liability if users' private information were breached, if confidential information about new product research leaked, etc.

    Microsoft lists the following risks to their business:

    Competition. If large organizations start using Google Docs etc. that would severely hurt Microsoftprofits.

    Product flops. Products they are developing could flop the way Surface and Windows 8.

    Legal action. MS is still in trouble in Europe for unlawful behavior.

    Patent infringement. MS may be infringing on other companies patents.

    Nowhere did it mention security as a risk that MS executives have on their radar screen at all. This is in marked contrast to Google and some others. Several "old guard" companies make no mention of how security issues could affect their business, while newer companies seem to be slightly more aware.

  7. Finally! by Tasha26 · · Score: 3, Insightful

    Don't care if it was an actual hack or a pretend-hack to leak information. Someone needs to lift the curtain on these thousands of law enforcement requests to Microsoft, Google, Yahoo and F***book.

  8. Re:e-mail for law enforcement? by Overzeetop · · Score: 2

    Yes, all the time (I am an expert witness). And they coordinate documents, meetings, etc. via email too.

    --
    Is it just my observation, or are there way too many stupid people in the world?
  9. Not Stolen by fred911 · · Score: 4, Interesting

    If they were stolen the owner wouldn't have possession or use of said items.

    --
    09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
  10. Documents Deliberately Released? by Anonymous Coward · · Score: 2, Insightful

    Former Microsoft SDE here. Given universal requirements for strong passwords, security briefings on social engineering, and sensitive document protection technologies employed internally at Microsoft, it seems equally likely to me that there was no actual breach of security. I would venture that these documents were deliberately released or left unguarded for hacktavists to easily find.

    1. Re:Documents Deliberately Released? by Anonymous Coward · · Score: 2, Informative

      Having worked with several MS security experts in my career, and given their near universal knowledge and somewhat Borg mentality concerning MS security practices, I would venture that you are correct. Except that it was not intentional, someone just REALLY pooched the goose and left the documents on a flash drive that got out while everyone was frantically looking for it.

      Oh the stories I have... MS employees and contractors are funny.

  11. Re:Annual report says MS unconcerned about securit by VortexCortex · · Score: 2

    Nowhere did it mention security as a risk that MS executives have on their radar screen at all.

    Of course not. Why would they be? They're the ones who make Windows.