• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

As U.S. Treasury intervened in the bond market, the Netherlands rushed 86 tons of gold out of America because of ‘geopolitical unrest’

2

'Critical employees will begin to retire': Trump’s new pay plan will deny most federal roles a raise, and it has workers warning of a retention crunch

3

One of MacKenzie Scott's latest donations takes her HBCU giving to well over $1 billion

1

As U.S. Treasury intervened in the bond market, the Netherlands rushed 86 tons of gold out of America because of ‘geopolitical unrest’

2

'Critical employees will begin to retire': Trump’s new pay plan will deny most federal roles a raise, and it has workers warning of a retention crunch

3

One of MacKenzie Scott's latest donations takes her HBCU giving to well over $1 billion
TechMicrosoft

Russian group behind the SolarWinds attacks is stepping up its attacks on U.S. government, Microsoft says

By
Jamie Tarabay
Jamie Tarabay
and
Bloomberg
Bloomberg
Down Arrow Button Icon
By
Jamie Tarabay
Jamie Tarabay
and
Bloomberg
Bloomberg
Down Arrow Button Icon
May 28, 2021, 5:10 AM ET
Google source logo
Add Fortune on Google for similar content.

The Russian hackers behind the SolarWinds campaign have escalated their attacks on U.S. federal agencies, think tanks and non-governmental organizations as part of intelligence gathering efforts on behalf of their government, Microsoft Corp. said late Thursday.

In a blog post, Microsoft Vice President Tom Burt said this past week’s attack—which is still ongoing—granted access to about 3,000 email accounts at more than 150 organizations by infiltrating a digital marketing service used by the U.S. Agency for International Development (USAID), called Constant Contact.

The hackers distributed phishing emails, among them “Special Alerts,” declaring that former President Donald J. Trump had published new documents on election fraud, and inviting the user to view them.

When clicked, a malicious file was inserted that the hackers could use to distribute a backdoor, granting the ability to steal data and infect other computers on the network.

While U.S. organizations bore the brunt of the attacks, victims in at least 24 other countries were also targeted, Burt wrote.

The Cybersecurity and Infrastructure Security Agency at the Department of Homeland Security posted news of the breach to its website and encouraged users to review Microsoft’s reporting and “apply the necessary mitigations.” Waltham, Massachussetts-based Constant Contact has made no public comment, and calls outside of business hours were not immediately answered.

Burt said it was clear that part of the hackers’ playbook was gaining access to trusted providers to infect their customers. Similarly in the SolarWinds campaign discovered in December 2020, hackers installed malicious code in updates for software belonging to Texas-based SolarWinds Corp., which was sent to tens of thousands of its customers, including nine federal agencies and at least 100 companies.

Accessing software updates and mass email providers gives the hackers increased chances of “collateral damage in espionage operations and undermines trust in the technology ecosystem,” Burt said.

The U.S. government said last month that SolarWinds was the work of SVR, the Russian foreign intelligence service, and said it also went by the names of APT29, which according to British intelligence spent much of last year hacking foreign governments for vaccine research, and Cozy Bear, which was involved in the 2016 hack of the Democratic National Committee.

In April, President Joseph Biden ordered sanctions against 32 Russian individuals and entities, including six companies that provide support to the Kremlin’s hacking operations. The U.S. also moved to expel 10 Russian diplomats working in Washington, including some intelligence officers. Biden and Putin are set to meet in Geneva in a little over two weeks’ time.

About the Authors
By Jamie Tarabay
See full bioRight Arrow Button Icon
By Bloomberg
See full bioRight Arrow Button Icon
Google source logo
Add Fortune on Google for similar content.

Latest in Tech


Most Popular

Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

    Latest in Tech


    Most Popular

    © 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
    FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.