PSA to orgs: if you use Microsoft 365, check your email logs for an email from mbsupport@microsoft.com

Microsoft are emailing tenant admin email addresses about a breach by Midnight Blizzard - you might not get the emails due to spam filtering etc.

reddit.com/r/microsoft/comment #threatintel

I would suggest orgs who use M365 want to check their Exchange Online logs for that email address.

Show thread

Just to be super clear, these are legit emails. Microsoft didn’t follow their M365 customer data breach notification process.

Show thread

Also, if you don’t use M365, check your email logs anyway.

Show thread

I’ve blown this up on LinkedIn now as it’s clear from talking to lots of impacted orgs they’ve found out about their breach from me.

The emails in the MS notification flow don’t even pass SPF, DKIM. It’s great that MS are being transparent — but they need to get down how to notify orgs.

linkedin.com/posts/kevin-beaum

Show thread

I know Mastodon didn’t look at the screenshot in this thread as they haven’t freaked out about CSAM being used as a job title 🤣

Show thread

My favourite part of this saga is aside from the MS breach notification emails not having valid DKIM signing nor SPF, the emails are getting flagged as phishing and submitted to sandboxes.

Each tenant has a unique URL, and I’m tracking over 500 so far - so there’s at least 500 victim orgs.

Show thread

I’ve had multiple people reach out to me to say Microsoft support have told them the email in the screenshot isn’t legit. It is.

Get the MS support team to talk to Redmond security team if you get caught in that loop.

Also, everybody dealing with this, drink.

Show thread

Is there any interest in a Signal group for people dealing with the Midnight Blizzard Microsoft email heist caper?

Show thread
Follow

@GossiTheDog Transparency from Microsoft should read, "We aren't very good at making software, so we leveraged a monopoly position to force all of you to use our operating systems and software. Now our hold is slipping due to a change in platform focus, that we couldn't keep up with (we really suck at software), so we must play at being contrite in hopes that one day we can again say, "Suck it, suckers!".

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml