UNITED STATES NEWS

Microsoft says early June disruptions to Outlook, cloud platform, were cyberattacks

Jun 19, 2023, 10:30 AM

(Photo by Steffen Trumpf/Getty Images)...

(Photo by Steffen Trumpf/Getty Images)

(Photo by Steffen Trumpf/Getty Images)

BOSTON (AP) — In early June, sporadic but serious service disruptions plagued Microsoft’s flagship office suite — including the Outlook email and OneDrive file-sharing apps — and cloud computing platform. A shadowy hacktivist group claimed responsibility, saying it flooded the sites with junk traffic in distributed denial-of-service attacks.

Initially reticent to name the cause, Microsoft has now disclosed that DDoS attacks by the murky upstart were indeed to blame.

But the software giant has offered few details — and did not immediately comment on how many customers were affected and whether the impact was global. A spokeswoman confirmed that the group that calls itself Anonymous Sudan was behind the attacks. It claimed responsibility on its Telegram social media channel at the time. Some security researchers believe the group to be Russian.

Microsoft’s explanation in a blog post Friday evening followed a request by The Associated Press two days earlier. Slim on details, the post said the attacks “temporarily impacted availability” of some services. It said the attackers were focused on “disruption and publicity” and likely used rented cloud infrastructure and virtual private networks to bombard Microsoft servers from so-called botnets of zombie computers around the globe.

Microsoft said there was no evidence any customer data was accessed or compromised.

While DDoS attacks are mainly a nuisance — making websites unreachable without penetrating them — security experts say they can disrupt the work of millions if they successfully interrupt the services of a software service giant like Microsoft on which so much global commerce depends.

It’s not clear if that’s what happened here.

“We really have no way to measure the impact if Microsoft doesn’t provide that info,” said Jake Williams, a prominent cybersecurity researcher and a former National Security Agency offensive hacker. Williams said he was not aware of Outlook previously being attacked at this scale.

“We know some resources were inaccessible for some, but not others. This often happens with DDoS of globally distributed systems,” Williams added. He said Microsoft’s apparent unwillingness to provide an objective measure of customer impact “probably speaks to the magnitude.”

Microsoft dubbed the attackers Storm-1359, using a designator it assigns to groups whose affiliation it has not yet established. Cybersecurity sleuthing tends to take time — and even then can be a challenge if the adversary is skilled.

Pro-Russian hacking groups including Killnet — which the cybersecurity firm Mandiant says is Kremlin-affiliated — have been bombarding government and other websites of Ukraine’s allies with DDoS attacks. In October, some U.S. airport sites were hit. Analyst Alexander Leslie of the cybersecurity firm Recorded Future said it’s unlikely Anonymous Sudan is located as it claims in Sudan, an African country. The group works closely with Killnet and other pro-Kremlin groups to spread pro-Russian propaganda and disinformation, he said.

Edward Amoroso, NYU professor and CEO of TAG Cyber, said the Microsoft incident highlights how DDoS attacks remain “a significant risk that we all just agree to avoid talking about. It’s not controversial to call this an unsolved problem.”

He said Microsoft’s difficulties fending of this particular attack suggest “a single point of failure.” The best defense against these attacks is to distribute a service massively, on a content distribution network for example.

Indeed, the techniques the attackers used are not old, said U.K. security researcher Kevin Beaumont. “One dates back to 2009,” he said.

Serious impacts from the Microsoft 365 office suite interruptions were reported on Monday June 5, peaking at 18,000 outage and problem reports on the tracker Downdetector shortly after 11 a.m. Eastern time.

On Twitter that day, Microsoft said Outlook, Microsoft Teams, SharePoint Online and OneDrive for Business were affected.

Attacks continued through the week, with Microsoft confirming on June 9 that its Azure cloud computing platform had been affected.

On June 8, the computer security news site BleepingComputer.com reported that cloud-based OneDrive file-hosting was down globally for a time.

Microsoft said at the time that desktop OneDrive clients were not affected, BleepingComputer reported.

United States News

FILE - Sweat covers the face of Juan Carlos Biseno after dancing to music from his headphones as af...

Associated Press

After summer’s extreme weather, more Americans see climate change as a culprit, AP-NORC poll shows

Kathleen Maxwell has lived in Phoenix for more than 20 years, but this summer was the first time she felt fear, as daily high temperatures soared to 110 degrees or hotter and kept it up for a record-shattering 31 consecutive days. “It’s always been really hot here, but nothing like this past summer,” said Maxwell, […]

44 minutes ago

Hudson, 7, left, Callahan, 13, middle, and Keegan Pruente, 10, right, stand outside their school on...

Associated Press

More schools are adopting 4-day weeks. For parents, the challenge is day 5

INDEPENDENCE, Mo. (AP) — It’s a Monday in September, but with schools closed, the three children in the Pruente household have nowhere to be. Callahan, 13, contorts herself into a backbend as 7-year-old Hudson fiddles with a balloon and 10-year-old Keegan plays the piano. Like a growing number of students around the U.S, the Pruente […]

3 hours ago

FILE - Sydney Carney walks through her home, which was destroyed by a wildfire on Aug. 11, 2023, in...

Associated Press

Residents prepare to return to sites of homes demolished in Lahaina wildfire 7 weeks ago

HONOLULU (AP) — From just outside the burn zone in Lahaina, Jes Claydon can see the ruins of the rental home where she lived for 13 years and raised three children. Little remains recognizable beyond the jars of sea glass that stood outside the front door. On Monday, officials are expected to begin lifting restrictions […]

3 hours ago

Associated Press

Kidnapped teen rescued from Southern California motel room after 4 days of being held hostage

SANTA MARIA, Calif. (AP) — Authorities rescued a 17-year-old boy in Southern California after he was kidnapped and held hostage for four days by captors who threatened to harm him if his family did not pay a $500,000 ransom. The teen was rescued Friday after law enforcement tracked him and his three kidnappers to a […]

8 hours ago

This Aug. 17, 2021 photo shows Quagga mussels cover the engine of a Bell P-39 Airacobra military pl...

Associated Press

Historians race to find Great Lakes shipwrecks before quagga mussels destroy the sites

An invasive mussel is destroying shipwrecks deep in the depths of the lakes, forcing archeologists and amateur historians into a race against time to find as many sites as they can before the region touching eight U.S. states and the Canadian province of Ontario loses any physical trace of its centuries-long maritime history.

9 hours ago

A sign marks a roadside rest stop that has been made to look like the historic security gate that a...

Associated Press

Birthplace of the atomic bomb braces for its biggest mission since the top-secret Manhattan Project

Los Alamos was the perfect spot for the U.S. government’s top-secret Manhattan Project.

13 hours ago

Sponsored Articles

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Importance of AC maintenance after Arizona’s excruciating heat wave

An air conditioning unit in Phoenix is vital to living a comfortable life inside, away from triple-digit heat.

Home moving relocation in Arizona 2023...

BMS Moving

Tips for making your move in Arizona easier

If you're moving to a new home in Arizona, use this to-do list to alleviate some stress and ensure a smoother transition to your new home.

Sanderson Ford...

Sanderson Ford

Sanderson Ford congratulates D-backs’ on drive to great first half of 2023

The Arizona Diamondbacks just completed a red-hot first half of the major league season, and Sanderson Ford wants to send its congratulations to the ballclub.

Microsoft says early June disruptions to Outlook, cloud platform, were cyberattacks